BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call

BitcoinWorld AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call AI shopping agent developer ORO has confirmed a significant security breach, los

AnonymousCryptoCompass newsroom
July 22, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

BitcoinWorldAI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call

AI shopping agent developer ORO has confirmed a significant security breach, losing approximately $630,000 worth of ALPHA tokens in an attack attributed to a North Korean state-backed hacking group. The incident, detailed in ORO’s internal incident report and first reported by Protos, highlights the increasingly sophisticated social engineering tactics used by cybercriminals to target cryptocurrency projects.

How the Attack Unfolded

According to ORO’s findings, the attack began when an employee received a message on Telegram from an acquaintance met at a previous offline conference. The hacker, impersonating a trusted contact, convinced the employee to join a video call. During this call, malware was deployed onto the employee’s device, granting the attackers access to internal systems and ultimately the company’s ALPHA token reserves.

ORO stated that the method aligns with known patterns of the Lazarus Group, a notorious North Korean hacking collective responsible for numerous high-profile crypto thefts. The use of social engineering—building trust through fake identities and leveraging real-world connections—marks a dangerous evolution in crypto-related cybercrime.

Implications for Crypto and AI Startups

This incident serves as a stark reminder that even early-stage AI projects with valuable token treasuries are prime targets. The attack exploited human trust rather than technical vulnerabilities, underscoring that security awareness training is as critical as software safeguards. For the broader crypto ecosystem, it reinforces the need for robust multi-signature wallets, hardware security modules, and strict verification protocols for any communication involving fund transfers.

ORO has since engaged with blockchain security firms and law enforcement to trace the stolen funds, though recovering tokens from state-sponsored actors is notoriously difficult. The company is also reviewing its internal security policies and employee communication guidelines.

Why This Matters to Investors and Users

For token holders and users of AI-driven platforms, this event highlights the real-world risks tied to digital assets. The theft not only impacts ORO’s operational capital but also shakes confidence in the security of emerging crypto-AI projects. Investors are advised to scrutinize a project’s security infrastructure and incident response history before committing funds.

Conclusion

The ORO hack is a textbook example of how North Korean cyber groups continue to target the cryptocurrency sector with precision. While the immediate financial loss is significant, the broader lesson for the industry is clear: human error, exploited through advanced social engineering, remains the weakest link in even the most technically sophisticated operations. ORO’s response and future security measures will be closely watched as a case study for other startups navigating the intersection of AI and blockchain.

FAQs

Q1: How did the hackers gain access to ORO’s funds?The attackers used a social engineering tactic: they contacted an ORO employee on Telegram, impersonating a known acquaintance, and convinced the employee to join a video call that installed malware on the employee’s device, allowing theft of ALPHA tokens.

Q2: Who is believed to be behind the attack?ORO attributes the attack to a North Korean state-backed hacking group, likely the Lazarus Group, which has a long history of targeting cryptocurrency exchanges and projects.

Q3: What steps should other crypto projects take to prevent similar attacks?Projects should implement strict verification for any communication involving fund transfers, use multi-signature wallets, provide regular security awareness training, and avoid relying solely on messaging apps for sensitive operational conversations.

This post AI Startup ORO Loses $630K in ALPHA Tokens After North Korean Hackers Exploit Telegram Video Call first appeared on BitcoinWorld.