Bitrefill has released a comprehensive report on a security breach that occurred on March 1, and it believes it to be the work of the North Korean hacking groupBitrefill has released a comprehensive report on a security breach that occurred on March 1, and it believes it to be the work of the North Korean hacking group

Bitrefill blames North Korean hackers for March 1 exploit, commits to cover losses

2026/03/18 07:35
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Bitrefill has released a comprehensive report on a security breach that occurred on March 1, and it believes it to be the work of the North Korean hacking group called the Lazarus Group. 

The Lazarus Group was also responsible for the largest single heist in crypto history when it hit Bybit early last year for more than $1 billion.

The company was transparent about how the incident occurred, but it did not disclose the exact amount stolen. Bitrefill claims its network was accessed through the compromised laptop of an employee, resulting in several hot wallets being drained. 

Did Bitrefill hide that it got hacked?  

Bitrefill has released a comprehensive post-mortem regarding a security breach that began on March 1. The company formally blamed the attack on the North Korean hacking group known as Lazarus Group or Bluenoroff because of the evidence it examined, based on the specific malware used, the modus operandi of the attackers, on-chain tracing of stolen funds, and the reuse of specific IP and email addresses previously linked to North Korean operations.

The incident began when an employee’s laptop was compromised and used as an initial point of entry for the hackers to gain access to a legacy credential. This credential granted the attackers access to a snapshot of the company’s systems that contained production secrets. 

With these secrets in hand, the Lazarus Group was then able to spread its access across Bitrefill’s infrastructure. They eventually reached parts of the company database and several cryptocurrency hot wallets.

Bitrefill’s security team first noticed the breach through “suspicious purchasing patterns” involving their suppliers. The attackers were exploiting the company’s gift card stock and supply lines. 

Simultaneously, the company realized that funds were being drained from their hot wallets and moved to wallets controlled by the attackers. 

In response, Bitrefill immediately took all systems offline to contain the threat, but due to the fact that the company’s global e-commerce network has thousands of products and dozens of suppliers, the process of safely shutting down and rebooting the infrastructure took over two weeks. 

How much was stolen during the Bitrefill breach?

Bitrefill’s investigation revealed that the hackers were not very interested in stealing customer data; not that they would have been able to. The company emphasized that its business model is designed to store very little personal information. It does not require mandatory “Know Your Customer” (KYC) documentation for most users, and data provided for higher-tier verification is managed by an external provider and was not stored on the systems that were breached.

However, the attackers did access approximately 18,500 purchase records. These records included customer email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. 

About 1,000 of Bitrefill’s customers who had to provide names for specific products had their data encrypted. However, because the hackers may have accessed the encryption keys, Bitrefill is treating that data as potentially compromised and has already emailed those affected.

Regarding financial losses, Bitrefill has announced that it will absorb the impact. Although hot wallets were drained, the company stated it remains well-funded and has been profitable for several years. All user balances remain safe and unaffected. 

Bitrefill worked with several high-profile security entities, including Zeroshadow, SEAL Org, and the Recoveris Team to map the movement of the stolen funds on the blockchain. They also assisted in the forensic cleanup of the company’s servers. 

Bitrefill has since tightened internal access controls to ensure a single compromise cannot lead to a full system breach. The company also improved its shutdown procedures to react faster to suspicious database requests.

The company also stated it is continuing to conduct thorough pentests (penetration tests) with external experts to find any remaining vulnerabilities. Currently, almost all services, including payments, stock replenishment, and account features have returned to normal. 

If you want a calmer entry point into DeFi crypto without the usual hype, start with this free video.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Stripe and Paradigm’s Tempo mainnet goes live for machine payments

Stripe and Paradigm’s Tempo mainnet goes live for machine payments

Stripe and Paradigm launch Tempo’s mainnet and the Machine Payment Protocol, targeting high-speed, stablecoin-based payments for AI agents and global enterprises
Share
Crypto.news2026/03/18 21:43
Pi Network Update: PiRC-101 Proposal Could Preserve MacroPi Value

Pi Network Update: PiRC-101 Proposal Could Preserve MacroPi Value

Pi Network Update: PiRC-101 Proposal Could Preserve MacroPi Value The Pi Network community has received a potentially significant development with the introduc
Share
Hokanews2026/03/18 20:52
Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise

Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise

The post Solana Treasury Firm Holdings Could Double as Forward Industries Unveils $4 Billion Raise appeared on BitcoinEthereumNews.com. In brief Forward Industries, the largest publicly traded Solana treasury company, filed to raise $4 billion through an at-the-market equity offering to expand its SOL holdings. The company’s stock (FORD) fell 8.2% following the announcement, while the proceeds could more than double the $3.1 billion currently held in Solana treasuries. DeFi Development Corp. also registered a preferred stock offering with the SEC, following similar funding tactics used by Bitcoin treasury companies like MicroStrategy. Forward Industries, the newest and largest publicly traded Solana treasury company, has filed to raise $4 billion through an at-the-market equity offering. For the sake of comparison, this $4 billion raise is nearly the same size as Bitcoin treasury Strategy’s Stride preferred stock raise in July. And it’s double the size of the Strife preferred stock offering the company did in May. The proceeds would be used for working capital; pursuit of its Solana token strategy, and “the purchase of income-generating assets to grow its business,” the company said in a press release. Forward Industries declined to comment to Decrypt on what other income-generating assets it’s considering adding to its balance sheet.  As markets opened Wednesday morning, Forward saw its stock price take a dive. The shares, which trade under the FORD ticker on the Nasdaq, dipped to $31.29 before rebounding to $34.28 at the time of writing—marking a 8.2% fall for the session. If the company sells all the shares and spends the bulk of the proceeds on buying Solana, it could more than double the amount of SOL being held in treasuries. At the time of writing, there’s already $3.1 billion in Solana treasuries, according to crypto price aggregator CoinGecko. Users on Myriad, a prediction market owned by Decrypt parent company DASTAN, have been growing more confident that SOL will reach $250 sooner than…
Share
BitcoinEthereumNews2025/09/18 12:43