ORO Hack Post-Mortem: The Sapphire Sleet Intrusion
2026-07-21 • ORO •
Sapphire Sleet used a compromised Telegram contact and a fake Microsoft Teams meeting to persuade an ORO team member to run a malicious AppleScript on macOS. The intrusion captured the system password, deployed a browser extension for keylogging, clipboard theft, screenshots, browser data collection, JavaScript injection, and remote command execution, and later established a persistent second-stage implant. The attacker ultimately stole the Bittensor SN15 owner wallet and sold 147,000 Alpha Tokens, while hardware-protected validator keys and other wallets and data remained unaffected. ORO attributes the operation with high confidence to the North Korean group based on overlap in the beaconing IP, payload, and infrastructure with Microsoft reporting, although the post does not disclose the indicator values.