ORO says North Korea-linked hack stole $630,000 after fake Teams update

ORO says North Korea-linked hack stole $630,000 after fake Teams update

The AI shopping agent developer said a compromised Telegram contact led a staff member to install malware, which later drained 147,000 Alpha tokens from software wallets tied to Bittensor.

TAO

Fact Check
All specific elements of the claim are corroborated by ORO's own post-mortem (reported by Protos and confirmed via ORO's official @oroagents X posts referenced there) and by the Bittensor-ecosystem taostats account: $630,000 / 147,000 Alpha tokens drained July 13, 2026, attributed to North Korean group Sapphire Sleet, entry via a compromised Telegram contact and fake Microsoft Teams update installing malware, with the owner key held in a software wallet due to limited Bittensor hardware support. Multiple independent reprints (Phemex, cryptonews) match. Sapphire Sleet is a well-documented North Korean actor per Microsoft. No conflicting sources found.
Summary

ORO said it lost $630,000 in crypto after a staff member was tricked into installing a malicious Microsoft Teams extension in an attack the company attributes with “high confidence” to Sapphire Sleet, a North Korean state-backed hacking group. The breach began after a team member met a legitimate contact at an industry conference in February 2025 and later resumed contact on Telegram. In May 2026, that contact’s compromised Telegram account sent a link for a call that mimicked Teams; after audio failed, the employee approved what appeared to be a Teams update, which installed malware on a macOS device. ORO said the extension logged keystrokes, monitored clipboard history, captured screenshots and browser activity, and could swap cryptocurrency addresses before the attacker drained 147,000 Alpha tokens on July 13. The company acknowledged its own security lapse, saying limited hardware wallet support in Bittensor forced it to temporarily keep the owner key in a software wallet, making it possible to exfiltrate from the compromised machine. ORO said its subnet remains fully operational, validator signing keys on hardware wallets were never exposed, and no other wallets, users, or subnet data were affected. It added that it is working with cryptocurrency exchanges, law enforcement, Opentensor, Curciible Labs, and Connito AI to pursue recovery of the stolen assets.

Terms & Concepts
  • software wallet: A crypto wallet stored on a device
  • hardware wallet: A physical device for offline key storage
  • social engineering: Manipulating people to gain unauthorized access