Table of Contents
Oro has published a full post-mortem on the security breach that compromised the owner wallet of Bittensor Subnet 15, attributing the attack with “high confidence” to the North Korean state-sponsored threat group Sapphire Sleet.
The attacker transferred and sold approximately 147,000 SN15 Alpha Tokens on July 13 after maintaining access to a team member’s computer for several weeks. Oro said the breach was limited to the subnet owner wallet and did not affect its validators, user information, subnet data, or ongoing operations.
“The subnet is fully operational,” Oro said. “No other wallets, and no user or subnet data, were affected.”
Attack Began With Fake Microsoft Teams Meeting
According to Oro’s investigation, the attack began on June 18, when a team member joined what appeared to be a call with a founder they had previously met at an industry conference.
The invitation came from the legitimate founder’s compromised Telegram account and directed the team member to a website designed to resemble Microsoft Teams. When the meeting audio failed to connect, the site prompted the team member to install a supposed Teams update.
The downloaded file was instead a malicious AppleScript that captured the team member’s system password and established elevated access to the machine. Five days later, the malware installed a browser extension capable of recording keystrokes, monitoring clipboard activity, taking screenshots, extracting browser storage and injecting JavaScript into webpages.
Oro said the attacker quietly collected cookies, credentials and wallet information before obtaining the seed phrase for the SN15 owner wallet.
On July 13, the attacker drained the wallet and sold the stolen Alpha Tokens into the subnet’s liquidity pool over approximately 10 hours. Oro detected the incident within minutes, and then worked over the next 24 hours to disable the remote access, quarantine the malicious extension, and began re-imaging devices and rotating credentials.
Oro Links Attack to Sapphire Sleet
Oro attributed the attack to Sapphire Sleet based on infrastructure and malware indicators recovered from the compromised computer.
Microsoft identifies Sapphire Sleet as a North Korean state actor known for targeting cryptocurrency, blockchain, financial and technology organizations. In a June 2026 update to its threat research, Microsoft described a new Sapphire Sleet campaign that used fake Teams meetings and malicious AppleScript updates to compromise macOS devices.

Oro said the command-and-control address used by the attacker, the recovered payload and other infrastructure overlapped with the campaign documented by Microsoft.
The attack also relied on the compromise of an existing relationship; the Oro team member had previously communicated with the founder whose Telegram account was later used to deliver the malicious meeting link.
Oro Takes Responsibility for Software Wallet Exposure
Oro said it had originally intended to place both its validator and subnet owner keys on hardware wallets after acquiring SN15. However, because of limited hardware-wallet support within Bittensor at the time, the team temporarily configured the owner key as a software wallet.
The validator signing keys remained on hardware wallets and were not exposed during the incident.
“This is what allowed it to be exfiltrated from a compromised machine,” Oro said. “That was inexcusable, and it was our mistake. We are sorry for the impact this has had on our community and our supporters.”
SN15 Moves to Multisignature Hardware Protection
Following the breach, Oro completed a coldkey swap transferring ownership of SN15 to a new wallet.
The team is also moving the subnet’s owner keys to a multisignature hardware configuration, which will require more than one authorized signer to approve transactions. Oro credited recent changes to the Bittensor SDK from Const for making multisignature protection easier to implement.
Oro also plans to place a Conviction lock on its owner emissions and deploy outbound firewalls across every team device. The company said outbound monitoring could have identified the infected machine’s communication with the attacker’s infrastructure within hours rather than weeks.
The team is working with Opentensor Foundation, Crucible Labs, Connito AI, cryptocurrency exchanges, law enforcement agencies and members of the Bittensor community in an effort to trace and recover the stolen assets.
Oro urged other subnet teams to be cautious of unexpected requests to install meeting software, SDKs or development tools, even when those requests appear to come from trusted contacts. It also recommended verifying downloads through a separate communication channel and avoiding files or instructions involving AppleScript, .scpt files or Terminal commands from unverified sources.
“This incident reinforced a hard lesson: building great products also requires continuously evolving our operational security,” Oro said. “Our priority now is rebuilding the community’s trust and continuing to ship improvements to the subnet.”