ORO

#ORO • 2026-07

In June 2026, attackers linked with high confidence to the North Korean state-backed group Sapphire Sleet used a compromised Telegram account of a legitimate industry contact to lure an ORO employee into a fake Microsoft Teams meeting, tricking them into manually running an AppleScript disguised as a Teams update that captured their macOS login password (May 28–June 18); over the following weeks the attackers installed a malicious browser extension that stole keystrokes, clipboard data, and credentials and could swap crypto addresses (June 22), then deployed a persistent second-stage implant (~June 25); on July 13 they drained the Bittensor SN15 owner wallet and sold 147,000 Alpha Tokens over roughly ten hours, though ORO detected and contained the breach the same day, limiting the damage to the owner wallet while validator signing keys on hardware wallets and all other wallets, user data, and subnet data remained unaffected, after which ORO terminated remote access, reimaged systems, rotated keys, completed a coldkey ownership swap, and coordinated with OpenTensor, exchanges, and law enforcement.

Related Actors

Related Reports

« Back