AI shopping agent developer ORO said it lost roughly $630,000 in crypto after a suspected North Korean state-backed hacker used a compromised Telegram account and a fake Microsoft Teams workflow to infiltrate a staff member’s computer. In its post-mortem, ORO said the breach ended with the theft of 147,000 Alpha tokens from the company’s wallets.
A conference contact became the entry point
According to ORO, one team member first met the contact at an industry conference in February 2025. The company described that relationship as legitimate, and said the two continued communicating on Telegram after the event.
Nearly a year later, in May 2026, the Telegram account belonging to that real contact reached out to arrange a catch-up call. ORO said the employee joined through a link that mimicked Microsoft Teams, but the call had no working audio, so the two agreed to reschedule.
Almost immediately afterward, the employee’s computer displayed a prompt to update Microsoft Teams. The staff member approved it, believing it was routine. ORO later wrote on X: “The worst part was, it was through someone we knew who's telegram was compromised. Regardless, won't happen in the future.”
The company said the contact’s Telegram account had in fact been compromised by the North Korean attacker, which allowed the social engineering setup to look credible.
Malicious extension monitored the machine for weeks
ORO said the supposed Teams update actually installed a malicious extension on the employee’s computer. That extension tracked keyboard input, monitored clipboard history, captured screenshots, reviewed browser history, and could replace cryptocurrency addresses.
The attacker then stayed quiet for almost a month, collecting data before moving funds. On July 13, ORO said, the hacker drained 147,000 Alpha tokens from the company’s crypto wallets.
ORO points to Sapphire Sleet
ORO said it still believes the original conference contact was genuine and that only the Telegram account had been taken over. On attribution, the company said it has “high confidence” that the attacker was Sapphire Sleet, a North Korean state-backed hacking group, based on the macOS intrusion observed in the case.
In ORO’s words: “The IP address that our compromised machine was beaconing to, the matching payload and some overlapping infrastructure outlined in the above post from Microsoft makes us confident that the attack came from this group.”
Microsoft Threat Intelligence has previously described Sapphire Sleet as using Teams-themed lures, social engineering, and a focus on macOS. Microsoft said: “By impersonating a legitimate software update, threat actors tricked users into manually running malicious files, allowing them to steal passwords, cryptocurrency assets, and personal data while avoiding built‑in macOS security checks.”

The firm said its own wallet setup contributed to the loss
ORO did not place all of the blame on the attacker. The company said part of the problem came from its own operational choices.
It said broad hardware wallet support was lacking in Bittensor, and that this led the firm, against its usual preference, to “temporarily” set the owner key as a software wallet instead. According to ORO, that decision made the key extractable from the compromised machine.
The company said: “This is what allowed it to be exfiltrated from a compromised machine. That was inexcusable, and it was our mistake. We are sorry for the impact this has had on our community and our supporters.”
Recovery efforts are under way
ORO said it is actively trying to recover the stolen assets with help from cryptocurrency exchanges and law enforcement. It also said it is working with Bittensor agent firm Opentensor, Bittensor wallet firm Curciible Labs, and Bittensor AI infrastructure firm Connito AI.
The company added that its subnet remains “fully operational,” that no other wallets, users, or subnet data were affected, and that validator signing keys stored on hardware wallets “were never exposed.”
Recent North Korea-linked incidents were also noted
The report placed the breach in the context of other recently exposed North Korea-related crypto cases.
In April, a North Korean mole known as “Moo” was exposed by crypto sleuth ZachXBT and was later fired from Solana-based decentralized exchange Stabble.
This month, crypto wallet firm MetaMask was also reported to have employed a North Korean mole as a developer for at least a month. According to a DeFi security analyst cited in the report, the developer’s links to Lazarus Group, another North Korea-based hacking group, had been publicly available for almost a year.

