AI shopping affiliate ORO disclosed on the X platform on July 21 that the company was targeted by a suspected North Korean hacker attack. On July 13, it lost 147k Alpha tokens, worth about $630k. The attackers gained access by compromising an ORO employee’s legitimate Telegram contact account, then sent a fake meeting link to trick employees into installing a malicious browser extension. After collecting data for nearly a month, they stole it.
According to ORO’s published post-incident analysis report, the full chain of this attack is as follows:
February 2025: An ORO employee met a contact at an industry conference, and the two established a normal communication relationship on Telegram
May 2026: The allegedly compromised Telegram account actively contacted the ORO employee and invited them to a video call
May 2026 to July 2026: ORO employees attempted to join the call using a link impersonating Microsoft Teams, but there was no audio. After the call, the computer prompted “Update Microsoft Teams.” After the employee accepted, they installed a malicious browser extension. The extension tracked keystrokes, clipboard history, and captured screenshots, and it could also alter encrypted wallet addresses. The attackers quietly collected data for nearly a month before stealing it.
July 13, 2026: The attacker stole 147k Alpha tokens (about $630k) from ORO’s encrypted wallet
In a statement, ORO admitted that, in order to adapt to the widespread lack of support for hardware wallets under the Bittensor protocol, it “temporarily” set the owner’s private keys to a software wallet instead of following the company’s internal security principle of prioritizing hardware wallets.
The original statement says: “It is precisely for this reason that data could be stolen from a machine that had been compromised. This is unforgivable, and it is our mistake.” ORO emphasized that the validator signing keys on the hardware wallet “were never leaked,” the subnet has been operating normally, and other wallet data and user data were not affected.
ORO said that, based on three technical indicators with “high confidence,” the attack came from the North Korea state-supported hacker group Sapphire Sleet: the IP address indicated by the beacon sent by the compromised machine, the matched malicious payload, and overlap with infrastructure previously recorded by Microsoft’s threat intelligence department.
Microsoft’s threat intelligence report states that Sapphire Sleet is skilled at conducting social engineering attacks using Teams themes, focuses on macOS targets, and tricks users into manually executing malicious files through spoofed software updates, in order to bypass macOS built-in security mechanisms.
According to ORO’s official statement, this attack only affected the company’s specific software wallets (due to a temporary setting that did not use a hardware wallet). Other wallets, user data, subnet data, and the validator signing keys on the hardware wallet were not affected. ORO said its subnet is currently operating completely normally.
In its post-incident analysis report, ORO said that, based on the IP address from the beacon sent by the compromised machine, the matched malicious payload, and overlap in infrastructure previously recorded by Microsoft threat intelligence, the company is “highly confident” the attacker was a member of Sapphire Sleet. Sapphire Sleet is a hacker group supported by the North Korean state.
ORO admitted that, due to insufficient hardware wallet support under the Bittensor protocol, the company “temporarily” violated its internal security principle by setting the owner’s private keys to a software wallet instead of a hardware wallet, which led to the keys being stolen after the computer was compromised. ORO said in its statement that this was an “unforgivable mistake” and formally apologized.
Related News
OpenAI discloses GPT-5.6’s breakthrough in the Sol sandbox, hacking into Hugging Face to steal benchmark answers
NAVER shares rise 5.3% as Coupang suffers a fire and faces fines, triggering a major shakeup in the landscape
South Korea Launches 150 Billion Won K-Culture Fund for AI Content
OpenAI AI Models Hack Hugging Face During Cybersecurity Test
The official website of Kenya’s president was taken offline by hackers, who are demanding a 5 BTC ransom