Cybersecurity R&D on Bittensor
A security system may work perfectly when it is launched and become noticeably less useful six months later. Attackers study how it behaves, discover which signals it relies on and gradually learn how to move around it. Bots begin to look more human. VPNs become harder to identify. Fraud networks spread their activity across hundreds of devices. AI makes much of this cheaper and easier to automate.
The uncomfortable reality of cybersecurity is that a defence cannot simply be built and considered finished. It has to be attacked repeatedly, preferably by people who are as inventive as the criminals trying to bypass it.
RedTeam uses Bittensor to organise that process as an open competition. Instead of relying entirely on an internal research team, Innerworks can publish security challenges and reward independent miners for finding better ways to deceive, test or improve detection systems. The subnet becomes something close to an external adversarial R&D laboratory: a place where useful attacks are discovered before they appear in the wild.
Of all the possible uses of Bittensor, this is one of the easier ones to understand. Cybersecurity is already a contest. RedTeam simply gives that contest an economic structure.
What does RedTeam do?
RedTeam is operated by Innerworks, a cybersecurity company focused on device intelligence, bot detection, location verification and fraud prevention. Its commercial product is designed to identify behaviour such as automated account creation, credential stuffing, synthetic identities, payment fraud and users attempting to disguise their real location through VPNs or proxies.
The subnet sits behind this product as a competitive research system. RedTeam creates technical challenges, miners submit code that attempts to solve them, and validators test the submissions inside isolated environments. According to the current documentation, miner code is submitted in encrypted form and only decrypted after a delay, which makes it harder for competing miners to copy a successful solution before it has been evaluated. Scores are based on performance relative to previous submissions, while older points decay over time so that miners have to continue improving rather than sit indefinitely on one clever discovery.
The active challenges reveal what this looks like in practice. RedTeam’s documentation currently lists work around automated-browser detection and network-traffic analysis, alongside earlier challenges involving device fingerprinting, anti-detect automation and the simulation of more human online behaviour.
Consider a company trying to stop automated account creation. Its detection system may initially recognise that a bot moves too quickly, uses an unusual browser configuration or behaves identically across many accounts. A RedTeam miner tries to conceal those signals. Another miner may build a browser that introduces more realistic timing and movement. A third may distribute activity across devices or routes that appear unrelated. Each successful bypass reveals something about the detector’s assumptions.
That discovery can then be used defensively. The company has effectively paid someone to break its system before an actual fraud network does.
This circular relationship between attack and defence is the centre of RedTeam. Miners are rewarded for discovering weaknesses; those weaknesses become research material for stronger detection; the improved detector creates a harder challenge for the miners. A well-designed subnet should keep this loop moving.
Why use Bittensor?
Cybersecurity companies already employ penetration testers, bug-bounty researchers and internal red teams. RedTeam is not inventing adversarial research. Its more interesting claim is that Bittensor can change the scale and continuity of that work.
An internal team is necessarily limited by hiring budgets, geography and the ideas already present inside the company. A conventional security audit may also be periodic: specialists test a system, deliver their findings and return months later. Attackers are not known for respecting the audit calendar.
A subnet can remain open continuously. Researchers from different countries can approach the same problem with different tools, programming styles and assumptions. Bittensor supplies the reward layer, while the subnet’s validators decide which contributions actually improve the state of the competition.
The commodity being produced here is difficult to package neatly. It is part exploit, part code, part adversarial technique and part evidence that a defensive system can be fooled. RedTeam therefore has a harder evaluation problem than a subnet selling a measurable resource such as storage or GPU time. Validators must establish that a submission works, that it is genuinely new and that it has not simply copied an earlier miner.
The project’s similarity checks, encrypted submissions, sandboxed evaluation and decaying scores are attempts to solve exactly that problem. The mechanism rewards miners who move the benchmark forward rather than those who repeatedly submit variations of yesterday’s answer. RedTeam’s public repository describes the subnet as performance-based and explicitly compares new solutions with previous and same-day submissions to discourage plagiarism.
This is where Bittensor adds something that a normal bug-bounty board does not. The competition is persistent, the rewards are distributed through the network and the incentive mechanism can be adjusted as new forms of attack become valuable. A challenge can be introduced when Innerworks encounters a new commercial problem and retired when it has stopped producing useful research.
In principle, RedTeam allows the company’s product needs to shape the work of an open population of security researchers.
RedTeam and Innerworks
Many Bittensor subnets face an awkward gap between the work miners perform and the products customers actually buy. A subnet may generate impressive benchmark results while leaving an outsider wondering where those results go afterwards.
RedTeam has a relatively clear answer. Innerworks sells the defensive product; RedTeam helps generate the adversarial intelligence used to improve it.
Innerworks describes the subnet as a “self-healing” adversarial R&D system that continuously simulates attack techniques including VPN evasion, synthetic identities and coordinated device networks. Its customer-facing platform then applies device fingerprinting, location intelligence and bot-activity analysis to areas such as account security, payments, SMS fraud and geographic compliance.
The relationship became more concrete through Innerworks’ partnership with 1inch. In October 2025, 1inch announced that it was integrating Innerworks’ predictive AI, device intelligence and RedTeam ethical-hacking tools into its security system. The stated purpose was to expose emerging hacker tactics and synthetic threats before they reached users.
That does not prove that every winning miner submission flows directly into 1inch or another customer product. The exact path from subnet output to commercial implementation remains difficult to inspect from outside. It does, however, show that Innerworks is selling a security layer in which RedTeam is presented as part of the underlying research process.
This commercial route gives the subnet more substance than a standalone cybersecurity tournament. The competition has a possible destination.
Why is RedTeam interesting?
Cybersecurity may be one of the fields where Bittensor’s competitive structure feels least artificial.
A language model can be judged in many ways, some of them rather subjective. A security bypass is more direct. Either the miner has found a way through the detector or it has not. The deeper challenge is determining whether that bypass represents a genuinely useful discovery and whether the validator’s test environment resembles the threats customers face in reality.
When that connection is strong, the subnet can turn attackers into a source of intelligence. A miner who successfully imitates human behaviour has exposed a weakness in bot detection. A miner who conceals a device farm has revealed which signals the existing fingerprinting model trusts too much. A miner who defeats a location check has produced information that can improve geo-compliance systems.
I find this a particularly convincing interpretation of what a subnet can become. Bittensor is often discussed as a marketplace for finished AI services: inference, storage, predictions or generated media. RedTeam instead uses it to coordinate the messy research that takes place before a product becomes stronger.
The subnet is essentially asking whether part of a company’s innovation process can be opened to continuous competition. Innerworks still has to define useful challenges, evaluate the results, integrate them into a reliable product and persuade customers to pay. Bittensor does not remove those responsibilities. It gives the company a larger and potentially more adaptive pool of adversarial researchers to draw from.
The quality of RedTeam will therefore depend less on how many attacks miners can generate than on how closely those attacks correspond to genuine customer problems. A subnet can become very good at winning its own benchmark while becoming less relevant to the outside world—a familiar problem across machine learning and, occasionally, crypto.
The Innerworks connection offers a plausible defence against that drift. When customers encounter new forms of fraud or automation, those problems can inform new subnet challenges. Miner research can then return to the commercial platform as improved threat intelligence. The distance between the competition and the market becomes shorter.
RedTeam’s most valuable output may ultimately be this feedback loop. Attackers force the subnet to adapt, the subnet helps Innerworks adapt, and the commercial product exposes the researchers to harder and more realistic problems. Cybersecurity has always evolved through that kind of pressure. RedTeam is testing whether Bittensor can organise it deliberately.
More information: https://innerworks.me/#redteam
