ORO, an AI shopping agent developer, revealed a $630,000 crypto loss after a suspected North Korean state-backed hacker exploited social engineering tactics to compromise an employee's device. The attack originated from a seemingly legitimate conference contact whose Telegram account had been hijacked, illustrating how threat actors can weaponize trusted relationships in highly targeted ways.

The incident began in February 2025 when a genuine contact was established at an industry event. Nearly a year later, in May 2026, this contact's Telegram account arranged a catch-up call via a link mimicking Microsoft Teams. The ORO staff member, unaware of the compromise, accepted a prompt to update Microsoft Teams, which in reality installed a malicious extension on their computer. This extension harvested sensitive data including keyboard inputs, clipboard contents, screenshots, and browser history, while also enabling the attacker to alter cryptocurrency addresses.

The Technical and Strategic Implications of the Breach

The attacker spent nearly a month collecting intelligence before draining 147,000 Alpha tokens from ORO's wallets on July 13. ORO identified the hacker as a member of Sapphire Sleet, a North Korean state-sponsored group known for macOS-targeted operations and social engineering involving Teams-themed lures. Microsoft’s Threat Intelligence corroborates this, highlighting how Sapphire Sleet bypasses macOS security by masquerading malicious payloads as legitimate software updates.

This attack shows significant vulnerabilities in operational security, especially when trusted communication channels are compromised. It also brings into focus the limitations of software wallets in decentralized protocols. ORO admitted that due to insufficient hardware wallet support within Bittensor, it temporarily used a software wallet for critical keys, which facilitated the exfiltration of assets. This case exemplifies the tangible risks that arise when cryptographic key management is compromised by infrastructure gaps.

By exploiting a trusted contact and standard business communication software, the hackers effectively bypassed traditional defenses. The incident raises concerns for organizations reliant on decentralized protocols and highlights the ongoing threat posed by sophisticated state-backed actors using social engineering combined with technical exploits.

This material is informational and does not constitute financial advice.