AI shopping agent developer ORO said it lost about $630,000 in a suspected North Korean hacking incident. According to ChainCatcher, attackers used a compromised Telegram account to send fake Microsoft Teams links to ORO employees, leading them to install a malicious extension that reportedly collected data for nearly a month before 147,000 Alpha tokens were stolen on July 13.

ORO said it believes the attack was carried out by the North Korean-linked Sapphire Sleet group. The company also acknowledged an internal security lapse, saying it temporarily switched owner keys to a software wallet because the Bittensor protocol did not adequately support hardware wallets, which allowed the keys to be stolen from a compromised computer.

ORO said it is working with exchanges, law enforcement, and Bittensor ecosystem partners to recover the stolen assets. It added that its subnet is still operating normally and that other wallets, user data, and validator signing keys were not affected.