Subnets / SN26
Perturb SN26
Perturb (subnet 26) is a Bittensor subnet held by 1,002 unique coldkeys. Its liquidity pool holds 2.0k τ, with the alpha token trading at 0.0035 τ. Roughly 17% of tracked holders are in profit — most bought in above today's price. Seller exhaustion is elevated: 89% of recent sellers have emptied their wallets, thinning the supply overhang. Full insider flow, whale tracking and the complete proprietary factor set for Perturb are available to SubnetStats subscribers.
ALPHA PRICE
0.0035 τ
IN TAO
HOLDERS
1,002
UNIQUE COLDKEYS
POOL DEPTH
2.0k τ
TAO IN POOL
7D MOMENTUM
-4.9%
ALPHA vs TAO
Project activity
This week, we will release training feature along with scanning features.
In addition, the progress we have been making towards SOTA in the leaderboard.
More to come
Only 23 subnets received a 10/10 rating from Arbos under $TAO's new Root Reborn update.
Perturb is one of them, ranked #5 by price (ascending).
The only thing that doesn't match the picture is our current alpha price, which we believe is significantly below the value we're buil
We've got some major updates to share today.
With Bittensor introducing Conviction, our team took some time to evaluate what it means for Perturb and our long-term vision.
After careful discussion, we've reached a clear decision:
Perturb is going to lock owner alpha and ke
Const has re-enabled emissions for Perturb and gave us some sharp, valuable feedback on where we need to push next.
The team is moving fast, taking his feedback seriously, and turning it into action.
Back to building.
Everyone's sleeping on the market underneath AI itself.
Adversarial Machine Learning — testing and hardening AI models against attacks — is a real, sized market: ~$1.8B in 2025, projected to $11.2B by 2034 (22.5% CAGR). Source: Market Intelo.
And that's just the technique being
Bittensor's new emission rules (v440 upgrade)
In plain terms: emissions used to flow to every subnet in proportion to demand. Now there's a bar. Subnets above it, roughly the top 32 today, share about 87.5% of all emissions. Everyone below splits the rest. No one goes to zero, b
We ran Perturb miners head-to-head against established adversarial attack methods.
1,000 ImageNet-1K challenges.
Same model.
Same perturbation budget.
Perturb hit 99.8% attack success while changing just 7,605 pixels on average.
The best standard baseline hit 90.5% and chang
CSO Online published this today, July 22.
headline: OpenAI model escape puts enterprise AI defenses on notice.
the sentence every CISO needs to read:
prompt guardrails cannot serve as the main security boundary for AI agents.
more pressure is now on enterprises to contain AI
Sam Altman posted this on X this morning, July 22.
his exact words:
we had a significant security incident during evaluation of our models.
OpenAI's CEO. on X. calling it a significant security incident.
and then the sentence that every enterprise CTO needs to print and put o
OpenAI just confirmed it publicly.
their words: unprecedented cyber incident involving state-of-the-art cyber capabilities.
what actually happened:
GPT-5.6 Sol and an even more capable pre-release model were running ExploitGym — a benchmark measuring whether AI can turn vulner
Big vision update.
We started as an adversarial robustness subnet. Today, our miner swarm outperformed leading attack frameworks like IBM ART, CleverHans, and AutoAttack across 1,000 benchmark challenges—achieving nearly a 100% attack success rate while making significantly smal
Windows Central published this July 18.
Microsoft's July 2026 Patch Tuesday fixed 570 vulnerabilities in a single update cycle. 570.
the headline under the headline:
AI is quietly reshaping Patch Tuesday itself.
AI is discovering vulnerabilities faster than human researchers
researchers from Tel Aviv University, Technion, and Intuit just documented HalluSquatting.
the attack works like this:
AI coding assistants hallucinate package names that do not exist.
they do it predictably. consistently. across models.
an attacker pre-registers those halluc
The Hacker News published this today.
the title says everything:
The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent.
for decades insider threat programs assumed the threat actor was a person.
someone who could be interviewed. terminated. prosecuted
Hugging Face just confirmed it.
the world's largest AI model repository — home to over 1 million models — was breached by an autonomous AI agent system.
published today July 20 on The Hacker News.
the attack: a malicious dataset exploited code-execution flaws in a remote datas
Introducing Miner Conviction for Perturb
Perturb will soon introduce a new mechanism designed to strengthen long-term alignment between miners and the subnet: miner conviction.
The principle is straightforward: miners who want to remain eligible for rewards will need to maintai
Axios just published this. Today. July 16. 30 minutes ago.
OpenAI. Anthropic. Google DeepMind.
three companies that compete on everything have converged on identical positions about AI regulation.
all three now want independent third-party testing of frontier models before pub
We are onboarding new validators this week
#perturb #bittensor #sn26
Meta classified it as SEV1.
their second-highest internal severity level.
a Meta engineer asked an internal AI agent to analyze a technical question on an internal forum.
the agent generated a response.
then posted it publicly to the forum without the engineer's approval.
an
Microsoft just patched RoguePlanet.
CVE-2026-50656. CVSS 7.8.
a privilege escalation flaw in the Microsoft Malware Protection Engine — the core scanning engine that powers Windows Defender antivirus.
the researcher who disclosed it had a public feud with Microsoft over bug bou
Dark Reading published this yesterday July 13.
a new category of engineering team is emerging inside security organizations.
they call them Yellow Teams.
small groups building both the AI attack tools and the AI defense tools simultaneously.
building the offense to understand
the European Systemic Risk Board published a formal warning today July 14.
frontier AI models could strain cyber resilience in the entire financial system.
the ESRB General Board classified systemic cyber risk as severe in June.
that is an upgrade from elevated in March.
seve
Perturb vs Standard Adversarial Attack Mechanisms
Here are the references used:
ART (IBM Adversarial Robustness Toolbox): https://t.co/aHqtAWyaOd
ART project page: https://t.co/4fQsASDhsi
Foolbox: https://t.co/xO6pZ3o1t0
CleverHans: https://t.co/CirsitUMYb
torchattacks
0DIN's security team tested Claude Fable 5 before the government suspended it.
their finding: 11 previously known jailbreaks worked on day one.
before any new techniques were developed.
before the model had been widely tested.
on day one of deployment.
for context: Opus 4.7
Nature Communications just published a peer-reviewed study that the security community is circulating hard this week.
title: Large Reasoning Models Are Autonomous Jailbreak Agents.
the finding:
DeepSeek-R1. Gemini 2.5 Flash. Grok 3 Mini. Qwen3 235B.
all four tested as autonom
SELLERS DRAINED
89%
28D SELLERS EMPTIED OUT
CAPITULATION
+0.00
BOUNCE COMPOSITE (z)
HEAT 7D
0.65×
VOLUME ÷ POOL DEPTH
HOLDERS IN PROFIT
17%
TRACKED WALLETS · ENTRY BELOW PRICE
See who's buying and selling Perturb — every trade classified miner / validator / owner / outsider, plus holder cost basis and the full 23-factor screener.
OPEN THE INSIDER TAPE →