ORO (SN15) released a post-mortem on the wallet hack that drained 147,000 $SN15 tokens, attributing the intrusion to Sapphire Sleet, an organized malicious actor known for targeting crypto and AI teams.
The attack started with a compromised Telegram account belonging to a real industry contact, then escalated through a fake Microsoft Teams meeting link that installed malicious software disguised as a routine update. The subnet itself stayed fully operational because validator signing keys were on hardware wallets and never exposed.
ORO (SN15) is now moving owner keys to multi-signature hardware protection and publishing the full breakdown specifically so no other Bittensor team gets caught by the same playbook.
How the Attack Was Orchestrated
The intrusion looked completely normal at every step, which is why it worked. The attacker used a real relationship, a familiar meeting workflow, and a delayed payload to bypass every instinct the team member would normally have.

1. A trusted contact reached out from a compromised Telegram account: The message referenced a real conference relationship and mentioned a startup in ORO’s exact vertical.
2. A fake Teams meeting link failed to connect: The team member ran what looked like a Teams update to fix the audio issue.
3. The update was not a Teams update: It captured the login password and installed itself quietly across the machine.
4. The payload waited five days before activating: By the time the malicious extension went live in the browser, the fake meeting was long forgotten.
5. The attacker waited weeks before draining the wallet: Cookies, keys, and eventually the wallet seed were pulled out slowly before the 147,000 $SN15 drain on July 13.
ORO (SN15) detected the drain within minutes of the sale and began containment immediately. Attribution to Sapphire Sleet is based on direct overlap between the recovered indicators and public research from Microsoft on the group’s macOS campaigns.
The Mistake ORO (SN15) Owned
The post-mortem is unusually direct about the specific decision that made the attack possible.
1. The plan was hardware wallets for both validator and owner keys. That is what ORO originally set up.
2. Bittensor did not yet widely support hardware wallets for owner keys. So the team kept the owner key on a software wallet as a temporary workaround.
3. That software wallet is what got exfiltrated. Everything else in the setup held. The workaround was the weak point.
ORO is completing a coldkey swap of SN15 ownership, moving the owner keys to multi-signature hardware protection with the latest Bittensor SDK, and adding a Conviction lock on owner emissions.
Per-host outbound firewalls are also going up on every machine as the control is most likely to catch this kind of attack in hours instead of weeks.
What Other Bittensor Teams Should Watch For
The whole reason ORO (SN15) published the post-mortem is so nobody else gets caught by the same playbook. The warnings are specific.
1. Unsolicited requests to install anything, even from trusted contacts. A compromised account is exactly why the alarm bells did not go off. The “I’m late for the meeting” pressure is part of the exploit.
2. Verify any download through a separate channel before running it. A different messaging app, a phone call, anything outside the compromised thread.
3. Signing keys stay on hardware wallets, no exceptions. Software wallets for anything valuable are the failure mode.
4. Multi-signature wallets require multiple people to be compromised. Recent SDK changes have made multisig significantly easier to set up.
Great Products Need Great Ops Security
The ORO (SN15) post-mortem reads as one of the more honest incident reports the Bittensor ecosystem has seen. Full attribution, complete ownership of the mistake, and a specific list of what changes going forward.
Sapphire Sleet has been active against crypto and AI teams for years, and the Teams-themed lure is now documented publicly enough that any subnet team can recognize the pattern before it lands.
For every operator holding keys or running validators on Bittensor, this is the kind of report worth reading before the next unsolicited catch-up call arrives in the DMs.
➛ Read the Full Report Here.
Enjoyed this article? Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox.
We respect your privacy. Unsubscribe anytime.
Enjoyed this article?
Join our newsletter
Get the latest TAO & Bittensor news straight to your inbox — every morning before markets open.





Be the first to comment