AI shopping agent developer ORO has reported a loss of approximately $630,000 in cryptocurrency following a cyberattack attributed to North Korean hackers. The breach occurred after an ORO employee was deceived into installing a malicious extension via a fake Microsoft Teams link sent through a compromised Telegram account. This led to the theft of 147,000 Alpha tokens on July 13. ORO suspects the attack was orchestrated by the North Korean hacking group Sapphire Sleet. The company acknowledged a security lapse, revealing that due to inadequate hardware wallet support in the Bittensor protocol, it temporarily used a software wallet for the owner key, which was subsequently compromised. ORO is collaborating with exchanges, law enforcement, and Bittensor partners to recover the stolen assets. The company assured that its subnet remains operational and that other wallets, user data, and validator signing keys were unaffected.