The AI shopping agent developer ORO has disclosed a significant security breach resulting in the theft of approximately $147,000 worth of cryptocurrency. The incident, which occurred earlier this month, has been attributed to the North Korean state-sponsored cybercriminal organization known as Sapphire Sleet. According to reports from Protos, the attackers utilized sophisticated social engineering tactics to compromise employee accounts and maintain persistent access to internal systems for several weeks before extracting assets from the Bittensor ecosystem.
Mechanism of the Cyberattack and Exploitation
The breach began when attackers utilized compromised Telegram accounts to send fraudulent Microsoft Teams meeting links to ORO staff members. These links were designed to trick employees into installing malicious browser extensions, allowing the hackers to exfiltrate sensitive data over a period of nearly one month. The culmination of the attack occurred on July 13, 2026, when the group successfully moved 147,000 Alpha tokens out of ORO’s control.
Investigation into the incident revealed several key factors:
- The use of social engineering to bypass initial perimeter defenses.
- Persistent data theft lasting nearly 30 days prior to the final transaction.
- The targeting of specific decentralized AI (DeAI) assets within the Bittensor network.
Security Oversight and Protocol Limitations
ORO representatives admitted that the theft was facilitated by a temporary deviation from internal security protocols. While the company typically mandates the use of hardware wallets for asset storage, they opted for a software-based owner key on a compromised computer. This decision was reportedly influenced by current limitations within the Bittensor protocol, which ORO claimed lacked sufficient hardware wallet support at the time of the configuration.
Sapphire Sleet is a notorious hacking collective frequently associated with the Democratic People's Republic of Korea (DPRK), often targeting the cryptocurrency sector to bypass international sanctions.
Recovery Efforts and Ecosystem Response
In the wake of the exploit, ORO has initiated a multi-agency response to track the stolen funds and mitigate further damage. The developer is currently collaborating with centralized exchanges (CEXs), law enforcement agencies, and technical partners within the Bittensor ecosystem. These efforts are focused on blacklisting the affected addresses and attempting to recover the 147,000 Alpha tokens before they are laundered through mixers or cross-chain bridges.
The incident serves as a stark reminder of the persistent threats facing the AI and blockchain convergence sector. Despite the loss, ORO stated they are reviewing their internal key management procedures to ensure that software wallets are no longer utilized for high-value administrative keys. The company continues to monitor the movement of the stolen assets on-chain while assisting authorities with the ongoing forensic investigation into the Sapphire Sleet operations.
Frequently Asked Questions
Quick answers to the most common questions about this topic.