
The AI shopping agent developer said a compromised Telegram contact led a staff member to install malware, which later drained 147,000 Alpha tokens from software wallets tied to Bittensor.
ORO said it lost $630,000 in crypto after a staff member was tricked into installing a malicious Microsoft Teams extension in an attack the company attributes with “high confidence” to Sapphire Sleet, a North Korean state-backed hacking group. The breach began after a team member met a legitimate contact at an industry conference in February 2025 and later resumed contact on Telegram. In May 2026, that contact’s compromised Telegram account sent a link for a call that mimicked Teams; after audio failed, the employee approved what appeared to be a Teams update, which installed malware on a macOS device. ORO said the extension logged keystrokes, monitored clipboard history, captured screenshots and browser activity, and could swap cryptocurrency addresses before the attacker drained 147,000 Alpha tokens on July 13. The company acknowledged its own security lapse, saying limited hardware wallet support in Bittensor forced it to temporarily keep the owner key in a software wallet, making it possible to exfiltrate from the compromised machine. ORO said its subnet remains fully operational, validator signing keys on hardware wallets were never exposed, and no other wallets, users, or subnet data were affected. It added that it is working with cryptocurrency exchanges, law enforcement, Opentensor, Curciible Labs, and Connito AI to pursue recovery of the stolen assets.