Bitrefill Breach Traced to Tactics Linked to Lazarus

Bitrefill Breach Traced to Tactics Linked to Lazarus

N
News Editor 01
2026-07-22 14:45:13
Bitrefill said its platform was breached on March 1 and disclosed the incident on March 17. The intrusion began with a compromised employee laptop, later reaching databases, hot wallets, and about 18,500 purchase records. Investigators said the attack shares traits seen in Lazarus-linked operations.
BitrefillLazaruscrypto securityhot walletsdata breach

Bitrefill said its platform was compromised on March 1, with the incident publicly disclosed on March 17. The company said forensic work and attribution remain the main priorities, and it has not released a confirmed estimate of financial losses. Early findings describe the intrusion as a coordinated and sophisticated operation.

The breach started with an employee laptop and expanded into production systems

According to the disclosed findings, the attackers first gained access through a compromised employee laptop. They extracted a legacy credential and used it to reach a snapshot containing sensitive production secrets. From there, access spread into broader infrastructure, including parts of internal databases and certain crypto wallets.

The first alert came from suspicious purchasing activity. Investigators found that gift card inventory and supply systems had been exploited, and hot wallets were drained into addresses controlled by the attackers. Bitrefill took systems offline to contain the incident. Internal findings indicate that financial assets, not user data, were the primary target.

Investigators see similarities to known Lazarus tradecraft

The company’s investigation said the attack resembles past operations associated with the Lazarus Group, also known as Bluenoroff. The overlaps cited in the source material include custom malware, a familiar attack chain of phishing followed by access, lateral movement, and extraction, as well as reused infrastructure such as IP addresses and email patterns.

On-chain tracing also identified suspicious fund movements, including chain-hopping behavior often associated with laundering activity tied to Lazarus-linked cases. The source notes that the group is widely known as a state-backed collective connected to some of the largest crypto-related breaches.

About 18,500 purchase records were accessed

Bitrefill said roughly 18,500 purchase records were accessed. The exposed data included limited details such as email addresses, crypto wallet information, and IP metadata. For around 1,000 transactions, encrypted names may also have been exposed because encryption keys may have been accessed. The company said affected individuals have already been notified.

It also said it stores minimal personal data and relies on external providers for KYC checks, which reduces the scope of direct data exposure. Users were advised to stay alert for suspicious messages, though the company said no immediate action is required at this stage.

External audits and penetration testing are now underway

In response, Bitrefill said it is carrying out external audits and penetration testing while tightening access controls, monitoring systems, and incident response procedures. The platform is known for letting users spend crypto on gift cards, mobile top-ups, and travel bookings. This case has put fresh attention on the security demands facing crypto payment platforms, especially around employee endpoints, secret management, and transaction monitoring.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.