ORO was attacked by the North Korean hacker group Sapphire Sleet, suffering a loss of $630k in cryptocurrency

TAO3.05%

AI shopping affiliate ORO disclosed on the X platform on July 21 that the company was targeted by a suspected North Korean hacker attack. On July 13, it lost 147k Alpha tokens, worth about $630k. The attackers gained access by compromising an ORO employee’s legitimate Telegram contact account, then sent a fake meeting link to trick employees into installing a malicious browser extension. After collecting data for nearly a month, they stole it.

Attack method: impersonated Microsoft Teams link, malicious browser extension, and data collection for nearly a month

According to ORO’s published post-incident analysis report, the full chain of this attack is as follows:

February 2025: An ORO employee met a contact at an industry conference, and the two established a normal communication relationship on Telegram

May 2026: The allegedly compromised Telegram account actively contacted the ORO employee and invited them to a video call

May 2026 to July 2026: ORO employees attempted to join the call using a link impersonating Microsoft Teams, but there was no audio. After the call, the computer prompted “Update Microsoft Teams.” After the employee accepted, they installed a malicious browser extension. The extension tracked keystrokes, clipboard history, and captured screenshots, and it could also alter encrypted wallet addresses. The attackers quietly collected data for nearly a month before stealing it.

July 13, 2026: The attacker stole 147k Alpha tokens (about $630k) from ORO’s encrypted wallet

ORO admits a security lapse: insufficient Bittensor hardware wallet support led to software wallet private keys being stolen

In a statement, ORO admitted that, in order to adapt to the widespread lack of support for hardware wallets under the Bittensor protocol, it “temporarily” set the owner’s private keys to a software wallet instead of following the company’s internal security principle of prioritizing hardware wallets.

The original statement says: “It is precisely for this reason that data could be stolen from a machine that had been compromised. This is unforgivable, and it is our mistake.” ORO emphasized that the validator signing keys on the hardware wallet “were never leaked,” the subnet has been operating normally, and other wallet data and user data were not affected.

Attribution of the attacker behind Sapphire Sleet: IP address, payload, and corroboration from Microsoft threat intelligence

ORO said that, based on three technical indicators with “high confidence,” the attack came from the North Korea state-supported hacker group Sapphire Sleet: the IP address indicated by the beacon sent by the compromised machine, the matched malicious payload, and overlap with infrastructure previously recorded by Microsoft’s threat intelligence department.

Microsoft’s threat intelligence report states that Sapphire Sleet is skilled at conducting social engineering attacks using Teams themes, focuses on macOS targets, and tricks users into manually executing malicious files through spoofed software updates, in order to bypass macOS built-in security mechanisms.

FAQ

Did the stolen Alpha token incident affect other users’ assets?

According to ORO’s official statement, this attack only affected the company’s specific software wallets (due to a temporary setting that did not use a hardware wallet). Other wallets, user data, subnet data, and the validator signing keys on the hardware wallet were not affected. ORO said its subnet is currently operating completely normally.

Why does ORO believe this attack came from Sapphire Sleet?

In its post-incident analysis report, ORO said that, based on the IP address from the beacon sent by the compromised machine, the matched malicious payload, and overlap in infrastructure previously recorded by Microsoft threat intelligence, the company is “highly confident” the attacker was a member of Sapphire Sleet. Sapphire Sleet is a hacker group supported by the North Korean state.

What was ORO’s own security responsibility in this ORO attack incident?

ORO admitted that, due to insufficient hardware wallet support under the Bittensor protocol, the company “temporarily” violated its internal security principle by setting the owner’s private keys to a software wallet instead of a hardware wallet, which led to the keys being stolen after the computer was compromised. ORO said in its statement that this was an “unforgivable mistake” and formally apologized.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments