According to Protos, AI shopping agent developer ORO released a post-incident report saying that due to an employee accidentally clicking a malicious software update disguised as Microsoft Teams while communicating with meeting contacts on Telegram whose accounts had already been compromised, computers were infected with a malicious extension. The extension lay dormant for nearly a month before stealing 147,000 Alpha tokens from ORO’s wallet on July 13, worth about $630k. ORO’s macOS intrusion analysis suggests the attack originated from the North Korean hacker group Sapphire Sleet. ORO also admitted that because the Bittensor ecosystem lacks sufficient support for hardware wallets, it temporarily set the owners’ keys to a software wallet, leading to the assets being stolen.

ORO-2.21%
TAO-0.29%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 3
  • 1
  • Share
Comment
Add a comment
Add a comment
ArbitrageFish
· 5h ago
On Telegram, they clicked a disguised “update” and lost hundreds of thousands of US dollars—this employee’s security awareness is way too poor. The company should put more effort into internal security training.
View OriginalReply0
TimeFrameTrader
· 5h ago
Hardware wallet support is the root problem. If the Bittensor ecosystem had been compatible earlier, even if only temporarily using a software wallet, it wouldn’t have been swept up all at once.
View OriginalReply0
  • Pinned