- AI shopping agent developer ORO lost $630,000 in crypto after a staff member installed a malicious Microsoft Teams extension.
- The attacker, believed to be a North Korean state-backed Hacker, compromised a legitimate conference contact’s Telegram account to initiate the months-long social engineering campaign.
- ORO admitted that using a software wallet instead of a hardware wallet for its owner key was an “inexcusable” mistake that enabled the July 13 theft of 147,000 Alpha tokens.
AI shopping agent developer ORO revealed it lost $630,000 worth of crypto after a suspected North Korean state hacker tricked a staff member into installing a malicious Microsoft Teams extension. According to a post-mortem released by ORO, a team member met a contact at a February 2025 industry conference and formed a legitimate relationship.
Nearly a year later in May 2026, the contact’s compromised Telegram account reached out to schedule a call. When the ORO staff member joined a call via a link mimicking Microsoft Teams, the audio failed, and the pair rescheduled. The team member then approved what appeared to be a Microsoft Teams update, which installed a malicious extension tracking keystrokes, clipboard history, and browser data.
The attacker quietly collected data for almost a month before draining ORO‘s wallets of 147,000 Alpha tokens on July 13. ORO claims with “high confidence” that the attack came from North Korea-backed group Sapphire Sleet, citing the macOS intrusion method, IP addresses, and overlapping infrastructure. Microsoft’s Threat Intelligence department has highlighted how Sapphire Sleet uses Teams-themed social engineering and focuses on macOS targets.
ORO partly admitted responsibility for the hack, noting that a lack of widespread hardware wallet support in the Bittensor protocol led it to “temporarily” establish the owner key as a software wallet. “This is what allowed it to be exfiltrated from a compromised machine. That was inexcusable, and it was our mistake.” The company is pursuing recovery with exchanges, law enforcement, and Bittensor partners Opentensor, Curciible Labs, and Connito AI.
This incident follows other recent North Korea-related crypto attacks. In April, Solana-based DEX Stabble fired a North Korean mole exposed by crypto sleuth ZachXBT, and this month, crypto wallet firm MetaMask was revealed to have employed a North Korean mole as a developer for at least a month.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
