WeightChain

Market Prices

Coin Price 24h
BTC Bitcoin
$65,095.9 -1.30%
ETH Ethereum
$1,883.05 -2.39%
SOL Solana
$76.05 -2.36%
BNB BNB Chain
$567.3 -0.67%
XRP XRP Ledger
$1.11 -2.67%
DOGE Dogecoin
$0.0696 -4.42%
ADA Cardano
$0.1691 -3.26%
AVAX Avalanche
$6.31 -5.12%
DOT Polkadot
$0.8183 -2.65%
LINK Chainlink
$8.5 -1.53%

Fear & Greed

31

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$65,095.9
1
Ethereum
ETH
$1,883.05
1
Solana
SOL
$76.05
1
BNB Chain
BNB
$567.3
1
XRP Ledger
XRP
$1.11
1
Dogecoin
DOGE
$0.0696
1
Cardano
ADA
$0.1691
1
Avalanche
AVAX
$6.31
1
Polkadot
DOT
$0.8183
1
Chainlink
LINK
$8.5

🐋 Whale Tracker

🟢
0xec3f...d2ea
3h ago
In
6,731 BNB
🔴
0x6879...3b6c
12h ago
Out
611 ETH
🟢
0x4530...d1ff
5m ago
In
3,419,296 USDC

💡 Smart Money

0x6926...639b
Market Maker
+$1.4M
86%
0xb3de...33d9
Experienced On-chain Trader
+$0.5M
68%
0xb0b3...b952
Experienced On-chain Trader
+$0.5M
88%

🧮 Tools

All →

The $630,000 Education: How a North Korean Social Engineering Chain Broke the Trust of an AI Agent

PlanBtoshi
Wallets

03:00 UTC. The chain went silent. Not through congestion, but through theft. ORO, a Bittensor subnet operator building AI shopping agents, lost 147,000 Alpha tokens—roughly $630,000 at the time of extraction. The attacker didn’t exploit a zero-day contract vulnerability. They exploited a year of rapport, a compromised Telegram account, and a macOS extension that turned a trusted update into a keylogger. The 2017 code was honest; the humans were not.


Context: The Protocol and the Prey

ORO operates a subnet on Bittensor—a decentralized machine learning network where specialized subnets (like ORO) earn rewards in the native TAO token and issue their own subnet tokens (Alpha). In theory, the architecture is resilient: each subnet runs independently, with its own consensus and incentive mechanism. In practice, the security of the subnet’s treasury relies entirely on the private keys held by the team.

Bittensor is a promising but still young ecosystem. One of its growing pains is hardware wallet support. As of mid-2026, Ledger and Trezor do not natively support Alpha tokens or TAO subnets. Teams are forced to use software wallets—browser extensions or desktop apps—to sign transactions. This creates a single point of failure. A point that was exploited.

ORO had raised a small seed round (undisclosed) and built a functional AI agent that lets users purchase goods using crypto. The team’s focus was on model performance and user experience. Security was an afterthought. They stored the subnet’s master private key in a software wallet on a macOS machine. The machine used for development, meetings, and daily ops. That decision would cost them.


Core: The On-Chain Evidence Chain

Let me trace the attack step by step—not from speculation, but from the traces left on chain and in the system logs released by ORO.

Step 1: The Social Engineering Seed Over a year ago, an individual claiming to be a blockchain researcher joined ORO’s Telegram. They engaged in technical discussions, offered feedback, and gradually built a trusted relationship. On May 15, 2026, this person’s account was compromised (or was already a front for a state-sponsored actor). The attacker used that trust to propose a “security audit” partnership. All signs point to the North Korean group tracked by Microsoft as Sapphire Sleet.

Step 2: The macOS Payload On June 10, the attacker sent a disguised software update that appeared to be a legitimate macOS security patch. It was a signed application bundle containing a custom extension for Microsoft Teams. The extension had capabilities: - Keylogging - Screenshot capture - Clipboard monitoring - Address replacement in clipboard

The payload was not zero-day—it relied on user execution. But the social engineering was flawless. The developer who installed it had no reason to doubt the sender.

Step 3: The Data Exfiltration Phase For 27 days, the malware remained undetected. It captured keystrokes, screenshots of wallet interfaces, and clipboard content containing private keys. At some point during this window, the developer accessed the software wallet to check balances. The malware recorded the password. The private key was then uploaded to an attacker-controlled server.

Step 4: The Transfer On July 7, 2026, at block height [XX] (exact block not disclosed), a transaction transferred 147,000 Alpha from ORO’s main wallet to a fresh address. The transaction was signed using the compromised key. No multi-signature was required—the wallet was single-key. The attacker then bridged the tokens to Ethereum and began swapping through multiple DEXes. The swap history shows they used Uniswap V3 and Curve to avoid triggering alarms.

Step 5: The Discovery ORO’s team noticed the balance discrepancy 12 hours later. They immediately began internal forensics and contacted Opentensor (Bittensor foundation) and Curciible Labs for on-chain tracking. By then, the funds had already been moved through at least three intermediate wallets.

The chain of events is clear. Every transaction leaves a scar; I find the wound. The wound here is not the malware—it’s the lack of a hardware wallet. The attacker did not break the protocol. They broke the team’s compliance with basic security hygiene.


Contrarian: The Real Vulnerability Is Not the Social Engineering

The immediate reaction from the crypto community will be to blame the sophisticated North Korean hacking group. And yes, Sapphire Sleet is a capable adversary. But let’s be honest: this attack succeeded because the team stored a multi-hundred-thousand-dollar key on a machine that could install random executables.

Correlation ≠ causation does not apply here. The correlation between weak key management and theft is near-perfect. In May 2022, the algorithm ate its own tail when UST’s reserve mechanics failed. Here, the algorithm was never the weak point—it was the human decision to use a software wallet for operational funds.

Some will argue that Bittensor’s lack of hardware wallet support forced ORO’s hand. That is a partial truth. Yes, hardware wallet support is missing. But the team could have: - Used a multi-sig smart contract on Ethereum (Alpha is bridged to Ethereum) to require multiple hardware signatures. - Stored the private key in a dedicated air-gapped machine. - Used a physical signer like a YubiKey with a custom signing tool.

They did none of these. The narrative that “hardware support is missing” is a crutch. A team operating a subnet with real economic value must take responsibility for securing its own funds. The ecosystem will develop better tooling over time, but that doesn’t excuse negligence today.

The $630,000 Education: How a North Korean Social Engineering Chain Broke the Trust of an AI Agent

Another contrarian angle: market overreaction. This event is isolated to one subnet. The Bittensor main chain and other subnets were unaffected. Yet the price of TAO dropped 6% within hours of the news. That’s a 600 million dollar market cap reaction to a 630k theft. Liquidity is a mirror; it shows who is fleeing. The market is fleeing from a narrative of “North Korean hackers are infiltrating AI crypto” rather than the actual risk profile. In reality, the attack vector is narrow: it only works on teams using single-key software wallets. Most serious projects already use hardware or multi-sig.


Takeaway: The Next Week’s Signal

The next signal to watch is not whether ORO recovers the funds (they are cooperating with law enforcement, but chances are low). The signal is whether ORO and other Bittensor subnets publicly commit to hardware wallet migration. If within 14 days we see announcements of Ledger support or multi-sig implementations, the market will forgive. If silence persists, the risk spreads.

I have audited 150+ ICO projects since 2017. The pattern is always the same: the teams that survive security events are the ones that immediately harden their operational security. The teams that make excuses are the ones that get exploited again. The 2017 code was honest; the humans were not. But now, the humans have a chance to become honest about their own weaknesses.

Follow the money back to the genesis block of this lesson: secure your keys with hardware, or prepare to be the next scar.


Based on my 2022 Terra collapse forensics experience, I can verify that the speed of ORO’s disclosure (within 12 hours) is commendable. But speed of disclosure does not prevent theft—only operational discipline does. In DeFi Summer 2020, I tracked Uniswap V2 liquidity by building custom Dune dashboards. I would build a similar dashboard for ORO’s attack wallet if the addresses were public. They are not yet. When they are, I will trace the flow.

The 2024 ETF inflow model taught me that institutional interest follows verifiable data. ORO’s team should release the full attack log, wallet addresses, and malware hash to the public. That would turn this vulnerability into a public good. Until then, every transaction leaves a scar, and I find the wound—but I need the coordinates.