Bitrefill Discloses Cyberattack Linked to North Korea's Lazarus Group: 18,500 Records Exposed

Bitrefill Discloses Cyberattack Linked to North Korea's Lazarus Group: 18,500 Records Exposed

N
News Editor 01
2026-07-02 18:45:14
Crypto e-commerce platform Bitrefill reported a cyberattack on March 1 originating from a compromised employee laptop. Attackers extracted legacy credentials to access production systems, internal databases, and hot wallets, stealing an undisclosed amount of funds and exploiting gift card inventory. Approximately 18,500 purchase records were breached, including email addresses, crypto payment addresses, and IP metadata; about 1,000 encrypted customer names were potentially exposed. Bitrefill linked the attack to North Korea's Lazarus Group based on malware signatures, reused infrastructure, and on-chain patterns. The company absorbed the losses, notified affected users, and implemented enhanced security measures. No evidence suggests full database exfiltration or that customer data was the primary target. According to Chainalysis, North Korea-linked groups stole over $2 billion in crypto in 2025.
BitrefillcyberattackLazarus GroupNorth Koreacryptocurrency securitydata breachhot walletChainalysis

Crypto e-commerce platform Bitrefill disclosed a cyberattack that began on March 1, resulting in stolen funds and limited exposure of customer data. The breach originated from a compromised employee laptop, according to the company's incident report. Attackers extracted legacy credentials tied to production systems, allowing them to escalate access across Bitrefill's infrastructure, including segments of its internal database and cryptocurrency hot wallets.

The attackers drained an undisclosed amount of funds from hot wallets and exploited the gift card inventory system to place suspicious purchases with vendors. Bitrefill did not specify the total financial impact but stated it would absorb the losses using operational capital. The intrusion was first detected through irregular purchasing patterns and anomalies in supplier activity. In response, Bitrefill temporarily took systems offline to contain the breach across its global operations. Services, including payments and account access, have since returned to normal.

What Data Was Exposed?

Approximately 18,500 purchase records were accessed. The exposed data includes email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. About 1,000 of those records involved encrypted customer names, which are being treated as potentially exposed due to the possibility that attackers accessed encryption keys. Bitrefill said it has notified affected users directly. Despite the breach, the company emphasized that it stores minimal personal data and does not require mandatory KYC (Know Your Customer) verification for most transactions. KYC-related information is handled by external providers and is not stored within Bitrefill's systems. The firm added there is no evidence that its full database was exfiltrated or that customer data was the primary target. “Based on our investigation and logs, we don’t have reason to think that customer data was the objective,” the company said, noting that the attackers appeared to conduct limited queries consistent with probing for valuable assets such as cryptocurrency holdings and gift card inventory.

North Korea's Lazarus Group Implicated

Bitrefill cited several indicators linking the attack to the Lazarus Group, including similarities in malware, reused infrastructure such as IP addresses and email accounts, and on-chain transaction patterns. The group, often associated with North Korea, has been tied to some of the largest crypto thefts in recent years through its specialized subgroup, Bluenoroff. Cybersecurity firms including zeroShadow, SEAL911, and RecoverisTeam assisted in the response and investigation, alongside on-chain analysts and law enforcement. The company said it is implementing additional security measures, including expanded monitoring systems and internal controls, to prevent similar incidents.

Escalating State-Sponsored Cyber Threats

The attack highlights ongoing concerns around state-sponsored cyber threats in the digital asset sector. According to blockchain analytics firm Chainalysis, groups linked to North Korea were responsible for more than $2 billion in crypto thefts in 2025, accounting for a significant share of total illicit activity in the space. Bitrefill said operations have stabilized following the incident, and customer activity and sales volumes have returned to typical levels. The company expressed confidence in its recovery.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.