Bitrefill Discloses Cyberattack: North Korea's Lazarus Group Suspected, 18,500 Purchase Records Exposed

Bitrefill Discloses Cyberattack: North Korea's Lazarus Group Suspected, 18,500 Purchase Records Exposed

N
News Editor 01
2026-07-02 19:00:14
Crypto e-commerce platform Bitrefill disclosed a cyberattack on March 1, 2026, originating from a compromised employee laptop. Attackers extracted legacy production credentials, gaining access to hot wallets and gift card systems, stealing an undisclosed amount of funds and accessing about 18,500 purchase records (including 1,000 encrypted customer names potentially exposed). Multiple indicators point to North Korea's Lazarus Group, including malware similarities, infrastructure reuse, and on-chain transaction patterns. Bitrefill temporarily took systems offline, recovered services, and absorbed losses with operational capital. Affected users have been notified. The incident highlights ongoing state-sponsored cyber threats in the digital asset sector.
BitrefillcyberattackLazarus GroupNorth Koreacryptocurrencydata breachhot walletsecurity incident

Bitrefill Cyberattack Overview

Crypto e-commerce platform Bitrefill has disclosed that it was the target of a cyberattack on March 1, 2026, originating from a compromised employee laptop. The attackers used stolen credentials to access legacy production systems, escalating their privileges across Bitrefill's infrastructure, including portions of its internal database and several cryptocurrency hot wallets.

According to the company's incident report, the attackers drained an undisclosed amount of funds from hot wallets while also exploiting gift card inventory systems to place suspicious purchases with vendors. Bitrefill did not specify the total financial impact but stated it will absorb the losses using operational capital. The intrusion was first detected through irregular purchasing patterns and anomalies in supplier activity.

In response, Bitrefill temporarily took its systems offline to contain the breach across its global operations. The company said services, including payments and account access, have since returned to normal levels.

As part of the attack, approximately 18,500 purchase records were accessed. The exposed data includes email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. Around 1,000 of those records involved encrypted customer names, which are being treated as potentially exposed due to the possibility that attackers accessed encryption keys. Bitrefill said it has notified affected users directly.

Despite the breach, the company emphasized that it stores minimal personal data and does not require mandatory know-your-customer verification for most transactions. Any KYC-related information is handled by external providers and is not stored within Bitrefill's systems. The firm added there is no evidence that its full database was exfiltrated or that customer data was the primary target. Investigation logs indicate attackers conducted limited queries consistent with probing for valuable assets such as cryptocurrency holdings and gift card inventory.

Involvement of North Korea's Lazarus Group

Bitrefill cited several indicators linking the attack to the Lazarus Group, including similarities in malware, reused infrastructure such as IP addresses and email accounts, and on-chain transaction patterns. The group, often associated with North Korea, has been tied to some of the largest crypto thefts in recent years through its specialized subgroup, Bluenoroff.

Cybersecurity firms including zeroShadow, SEAL911, and RecoverisTeam assisted in the response and investigation, alongside on-chain analysts and law enforcement. The company said it is implementing additional security measures, including expanded monitoring systems and internal controls, to prevent similar incidents.

According to blockchain analytics firm Chainalysis, groups linked to North Korea were responsible for more than $2 billion in crypto thefts in 2025, accounting for a significant share of total illicit activity in the space. Bitrefill said operations have stabilized following the incident and expressed confidence in its recovery, noting that customer activity and sales volumes have returned to typical levels. The attack underscores ongoing concerns around state-sponsored cyber threats in the digital asset sector.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.