Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy

Bitrefill accuses North Korea-linked Lazarus hacker group for compromising 18,500 purchase records

CN
coindesk
Follow
11 hours ago
AI summarizes in 5 seconds.


What to know : Bitrefill said a March 1, 2026 cyberattack linked to North Korea’s Lazarus Group compromised parts of its infrastructure, drained some hot wallets and exposed about 18,500 purchase records. The breach began with a compromised employee laptop that revealed legacy credentials, allowing attackers to access production keys, exploit gift card supply chains and move funds before the company took systems offline. Bitrefill will cover the losses from operational capital.

Cryptocurrency payments and gift card platform Bitrefill has blamed the North Korea-linked hacking group Lazarus for a cyberattack on March 1, 2026, that compromised parts of its infrastructure and cryptocurrency wallets.

The attackers gained access to production keys, transferred funds from hot wallets, and exposed 18,500 purchase records containing emails, payment addresses, and IP addresses.

Approximately 1,000 records included encrypted usernames. Affected users were notified. Operations have resumed, with the company announcing to cover losses from operational capital. The incident underscores the importance of vigilance regarding crypto and on-chain security.

The modus operandi included malware, on-chain tracing and reused IP and email addresses and was similar to previous attacks attributed to North Korea’s Lazarus Group, also known as Bluenoroff, the company said in a detailed report on X.

The Lazarus Group has previously targeted crypto projects including Ronin Network, Harmony’s Horizon Bridge, WazirX, and Atomic Wallet.

How the attack unfolded

It all began with with a compromised employee laptop, which exposed legacy credentials and allowed attackers to access Bitrefill’s broader infrastructure, including parts of its database and cryptocurrency wallets.

The breach quickly became apparent when the company noticed unusual purchasing patterns among certain suppliers, signaling that attackers were exploiting its gift card inventory and supply chains. The firm also noted that attackers were draining some hot wallets and moving funds to their own addresses, following which, the system was taken offline to contain the damage.

“Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial,” the company said in a statement.

Since the incident, Bitrefill has been working with security researchers, incident response teams, on-chain analysts, and law enforcement to investigate the breach.

Customer data impact

Hackers accessed a small set of purchase records, approximately 18,500, containing

Bitrefill said there is no evidence that customer data was a primary target. Its logs indicate that attackers ran a limited number of queries aimed at cryptocurrency holdings and gift card inventory rather than extracting the entire database.

The platform stores minimal personal data and does not require mandatory KYC. A small subset of purchase records, approximately 18,500, was accessed, containing information such as email addresses, crypto payment addresses, and metadata including IP addresses. About 1,000 records contained encrypted names for specific products; the company is treating this data as potentially compromised and has notified affected customers directly by email.

At present, Bitrefill does not believe customers need to take any additional action, though it advises caution regarding unexpected communications related to Bitrefill or cryptocurrency.

Steps to strengthen security

In response to the breach, Bitrefill said it has already strengthened its cybersecurity practices and is working to draw lessons from the incident.

The company outlined several measures, including conducting comprehensive penetration tests with external experts, tightening internal access controls, enhancing logging and monitoring for faster threat detection, and refining incident response procedures and automated shutdown protocols.

Looking forward

Bitrefill acknowledged that this was its first major attack in more than a decade of operation but stressed that it remains well-funded and profitable, capable of absorbing operational losses. Most systems, including payments, stock, and accounts, are back online, with sales volumes returning to normal.

“Getting hit by a sophisticated attack sucks (a lot),” the company said. “But we survived. We will continue to do our best to continue deserving our customers’ trust."

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

龙虾一键接入,助交易稳赚
广告
|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Selected Articles by coindesk

8 minutes ago
Sam Bankman-Fried\\\'s bankrupt exchange FTX set to repay creditors $2.2 billion this month
56 minutes ago
Kalshi co-founder fights back against Arizona’s ‘overstep’ in what a lawyer calls a federal-state turf war
1 hour ago
Federal Reserve holds policy steady as it balances growth and inflation concerns
View More

Table of Contents

|
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Related Articles

avatar
avatarcoindesk
8 minutes ago
Sam Bankman-Fried\\\'s bankrupt exchange FTX set to repay creditors $2.2 billion this month
avatar
avatarbitcoin.com
14 minutes ago
From $76K to $71K: Is Bitcoin Losing Its ‘Safe Haven’ Status to Macro Reality?
avatar
avatarbitcoin.com
34 minutes ago
Court Reaffirms Bitcoin’s Status as Property but Limits Tort Claims in $172M Case
avatar
avatarcoindesk
56 minutes ago
Kalshi co-founder fights back against Arizona’s ‘overstep’ in what a lawyer calls a federal-state turf war
avatar
avatarDecrypt
1 hour ago
Bitcoin, Ethereum Waver as Fed Holds Interest Rates Steady
APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink