ORO Hack: Suspected North Korean Hacker Steals $630K in Crypto
AI company ORO says a suspected North Korean hacker stole $630,000 in crypto after fooling an employee with a fake Microsoft Teams update. First, the attacker hijacked a known contact’s Telegram account. Then that existing relationship became the way into an ORO computer. The scheme worked. I’ll be honest: blockchain security sounds far less reassuring when someone controls the laptop connected to the wallet.

It started with a normal meeting. In February 2025, an ORO employee met a contact at an industry conference, and the two stayed in touch through Telegram. In May 2026—more than a year later—the contact’s account sent a message asking to schedule a call. Nothing about that request seemed obviously suspicious. ORO later said the account had been compromised.
The employee clicked what appeared to be a Microsoft Teams link. No audio. Both sides agreed to try the call again later, and almost immediately, a Teams update prompt appeared. The employee approved it. That fake update installed a malicious extension. Most security advice says not to click unfamiliar links. That’s only half right: this link appeared to come from someone the employee actually knew.
The extension recorded keystrokes and clipboard activity. It also took screenshots. More critically, it replaced copied crypto addresses with addresses controlled by the attacker. Then came the patient part: the hacker waited nearly a month. On July 13, the attacker drained ORO’s wallets of 147,000 Alpha tokens worth about $630,000.
ORO attributed the attack to Sapphire Sleet, a North Korean state-backed hacking group, with “high confidence.” Its evidence included IP addresses and related malicious payloads, plus common infrastructure. The findings also matched Microsoft threat intelligence describing the group’s use of macOS malware and fake Teams calls. Why does that matter? Because the technical trail points to a practiced operation, while the con itself remained brutally simple: steal a trusted identity, manufacture a minor problem, then offer a believable fix.
North Korean operatives have already surfaced inside crypto companies. In July 2026, wallet developer MetaMask said it had unknowingly employed a North Korean operative for at least a month. Three months earlier, Stabble—a decentralized exchange built on Solana—found an operative known as “Moo” inside the company. This was not isolated.
These cases complicate crypto’s safe-haven pitch. Investors sometimes buy Bitcoin (BTC) when political tensions rise; Bitcoin gained 8% around the January 2020 strike that killed Iranian general Qassem Soleimani. Yet governments seeking to evade sanctions or raise money outside the banking system are drawn to the same border-crossing features. Counter to the usual pitch, operating beyond parts of traditional finance does not make the surrounding people or laptops secure. Wallets are another weak point. Once access is gained, the money can move very quickly.
ORO admitted its own custody decision helped make the loss possible. Bittensor, the decentralized protocol it uses, did not broadly support hardware wallets. ORO therefore stored the owner key “temporarily” in a software wallet. My take: those quotation marks around “temporarily” carry a lot of weight, because malware on the infected computer could steal that key directly.
“This is what allowed it to be exfiltrated from a compromised machine. That was inexcusable, and it was our mistake,” ORO said.
The admission may trigger fresh calls for tighter security rules. Companies and governments are testing more uses for digital assets, but basic protections still vary widely. ORO builds an AI shopping agent, not a crypto exchange. Even so, it held 147,000 Alpha tokens worth about $630,000—enough to attract a state-backed attacker. The software wallet supplied the opening.
Bittensor and similar protocols may now face pressure to support hardware wallets for sensitive keys. Regulators could also consider minimum custody standards for organizations holding large crypto balances. Would those rules stop every convincing fake update? No. Keeping owner keys off ordinary work computers would, however, close one obvious route for attackers. Sometimes the boring control matters most.
The worst part was, it was through someone we knew who’s telegram was compromised.
Regardless, won’t happen in the future.
– ORO (@oroagents) July 21, 2026
ORO is working with law enforcement and several crypto organizations to recover the assets. It named Opentensor and Curciible Labs as participants in the effort. Connito AI was also named. According to the company, its subnet remains “fully operational.” The attacker did not access other wallets or user information; subnet data was not reached either. Validator signing keys stayed on hardware wallets and were “never exposed.” That distinction is hard to ignore.
What this means
The ORO theft required no broken blockchain and no breached exchange. It required patience, a stolen Telegram account and software disguised as routine. That’s the worrying part. State-backed hackers are targeting the messaging and video-call tools crypto workers use every day because compromising Microsoft Teams or Telegram may be easier than attacking the network underneath them.
For investors, securing the wallet is not enough. Yes, that sounds like it contradicts the usual wallet-first advice—bear with me. The computer accessing that wallet matters just as much. So do its browser extensions. Every update prompt deserves scrutiny. Large holdings belong on hardware wallets when the protocol supports them; without that support, users are accepting a real custody risk for convenience.
Bittensor now has a specific engineering problem to solve. Stronger hardware-wallet support could prevent a stolen computer key from becoming another six-figure loss. Until that option becomes standard, investors may view Alpha and other tokens in the ecosystem as harder to protect than assets backed by established custody tools. I wouldn’t dismiss the market effect: demand could weaken even though nobody breached the protocol itself.
Investigators must trace and recover the 147,000 Alpha tokens. If they succeed, the case could give other victims a practical model for coordinating with law enforcement and token issuers. Validators would have a role as well. If the funds disappear, though, attackers may conclude that the same trick is worth repeating.
Traders should watch the market response to the next large hacks. A cluster of incidents could push some investors toward Bitcoin or stablecoins temporarily, although both retain custody risks. Warnings from Microsoft and other communication-platform providers deserve attention too. Why did the fake call work? Because Teams looked familiar. No exotic vulnerability was required.
The chase will probably be slow and repetitive. North Korean groups change tactics; security teams respond. Then another believable message lands in an inbox or Telegram chat. What stands out to me is how little the attacker needed: one stolen contact and one approved update. The result was a $630,000 loss.
