The post Crypto Platform Bitrefill Hacked: 18,500 User Records Exposed in Cyberattack appeared first on Coinpedia Fintech News Crypto payments platform BitrefillThe post Crypto Platform Bitrefill Hacked: 18,500 User Records Exposed in Cyberattack appeared first on Coinpedia Fintech News Crypto payments platform Bitrefill

Crypto Platform Bitrefill Hacked: 18,500 User Records Exposed in Cyberattack

2026/03/18 16:56
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
North Korean Lazarus Group Targets LinkedIn In Yet Another Crypto-malware Campaign

The post Crypto Platform Bitrefill Hacked: 18,500 User Records Exposed in Cyberattack appeared first on Coinpedia Fintech News

Crypto payments platform Bitrefill has confirmed a major cyberattack on March 1, 2026, with signs pointing to the North Korea-linked Lazarus Group. The Bitrefill attack exposed internal systems, drained crypto wallets, and accessed around 18,500 user records. Let’s understand how the Bitrefill hack happened and whether user data is safe.

How the Bitrefill Hack Happened?

The Bitrefill hack began in a simple but most dangerous manner, through a compromised employee’s laptop. In an X post, Bitrefill said Hackers managed to steal old login credentials, which gave them access to internal systems. 

Stolen login details helped attackers enter internal systems and move deeper into the company’s infrastructure.

From there, they accessed parts of the database and crypto hot wallets, allowing them to transfer funds to external addresses.

As the attack happened, the company first noticed unusual activity when attackers started misusing its gift card system. At the same time, funds were being moved from hot wallets.

Once detected, Bitrefill quickly took all systems offline to stop further damage and secure its platform.

18,500 User Records Exposed

Bitrefill confirmed that about 18,500 purchase records were accessed. This data included email IDs, crypto wallet addresses, and technical details such as IP addresses. 

In around 1,000 cases, customer names may also have been exposed. The company said this data was encrypted but still treated as potentially compromised.

Despite the breach, Bitrefill said it stores very little personal data and does not require full KYC. Any sensitive user data is kept with external providers, not on its own systems.

Lazarus Group Suspected of Being Behind This Attack

Following the attack pattern, Bitrefill said the incident shows strong similarities to past attacks linked to the North Korea state-sponsored Lazarus Group.

These similarities include malware patterns, reused systems, and on-chain fund movements.

Bitrefill Began an Investigation Following The Hack

Further, in a post, Bitrefill said it began working with cybersecurity experts, blockchain analysts, and law enforcement to investigate the breach.

The company is now improving its system by adding stronger controls, more robust monitoring, and faster response plans.

For users, Bitrefill said there is no need for immediate action but advised staying alert for phishing emails or suspicious messages.

Never Miss a Beat in the Crypto World!

Stay ahead with breaking news, expert analysis, and real-time updates on the latest trends in Bitcoin, altcoins, DeFi, NFTs, and more.

bell icon Subscribe to News

FAQs

What happened in the Bitrefill hack?

On March 1, 2026, Bitrefill suffered a cyberattack where hackers used stolen employee login credentials to access internal systems, drain crypto hot wallets, and view around 18,500 user purchase records.

Is my personal data safe after the Bitrefill breach?

Bitrefill stores minimal personal data and does not require full KYC. While email addresses and wallet addresses were exposed, sensitive information is kept with external providers, reducing the risk of identity theft.

Who was behind the Bitrefill crypto wallet attack?

Security experts suspect the North Korea-linked Lazarus Group is responsible. Bitrefill noted the attack matched their patterns, including specific malware signatures and methods used to move stolen cryptocurrency funds.

What should Bitrefill users do after the hack?

Users should stay alert for phishing emails, avoid suspicious links, and monitor accounts. No immediate action is required, but caution is strongly advised.

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0,0002948
$0,0002948$0,0002948
-1,27%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum spot ETFs had a total net outflow of $1.8898 million yesterday, with Fidelity FETH leading the way with a net outflow of $29.1892 million.

Ethereum spot ETFs had a total net outflow of $1.8898 million yesterday, with Fidelity FETH leading the way with a net outflow of $29.1892 million.

PANews reported on September 18 that according to SoSoValue data, the total net outflow of Ethereum spot ETF was US$1.8898 million yesterday (September 17, US Eastern Time). The Ethereum spot ETF with the largest single-day net inflow yesterday was Blackrock ETF ETHA, with a single-day net inflow of US$25.8636 million. The current historical total net inflow of ETHA has reached US$13.255 billion. The second is Grayscale Ethereum Mini Trust ETF ETH, with a single-day net inflow of US$6.382 million. The current historical total net inflow of ETH has reached US$1.431 billion. The Ethereum spot ETF with the largest single-day net outflow yesterday was the Fidelity ETF FETH, with a single-day net outflow of US$29.1892 million. The current historical total net inflow of FETH has reached US$2.768 billion. As of press time, the total net asset value of the Ethereum spot ETF was US$29.719 billion, the ETF net asset ratio (market value as a percentage of Ethereum's total market value) reached 5.47%, and the historical cumulative net inflow has reached US$13.659 billion.
Share
PANews2025/09/18 11:54
Michael Saylor Pushes Digital Capital Narrative At Bitcoin Treasuries Unconference

Michael Saylor Pushes Digital Capital Narrative At Bitcoin Treasuries Unconference

The post Michael Saylor Pushes Digital Capital Narrative At Bitcoin Treasuries Unconference appeared on BitcoinEthereumNews.com. The suitcoiners are in town.  From a low-key, circular podium in the middle of a lavish New York City event hall, Strategy executive chairman Michael Saylor took the mic and opened the Bitcoin Treasuries Unconference event. He joked awkwardly about the orange ties, dresses, caps and other merch to the (mostly male) audience of who’s-who in the bitcoin treasury company world.  Once he got onto the regular beat, it was much of the same: calm and relaxed, speaking freely and with confidence, his keynote was heavy on the metaphors and larger historical stories. Treasury companies are like Rockefeller’s Standard Oil in its early years, Michael Saylor said: We’ve just discovered crude oil and now we’re making sense of the myriad ways in which we can use it — the automobile revolution and jet fuel is still well ahead of us.  Established, trillion-dollar companies not using AI because of “security concerns” make them slow and stupid — just like companies and individuals rejecting digital assets now make them poor and weak.  “I’d like to think that we understood our business five years ago; we didn’t.”  We went from a defensive investment into bitcoin, Saylor said, to opportunistic, to strategic, and finally transformational; “only then did we realize that we were different.” Michael Saylor: You Come Into My Financial History House?! Jokes aside, Michael Saylor is very welcome to the warm waters of our financial past. He acquitted himself honorably by invoking the British Consol — though mispronouncing it, and misdating it to the 1780s; Pelham’s consolidation of debts happened in the 1750s and perpetual government debt existed well before then — and comparing it to the gold standard and the future of bitcoin. He’s right that Strategy’s STRC product in many ways imitates the consols; irredeemable, perpetual debt, issued at par, with…
Share
BitcoinEthereumNews2025/09/18 02:12
Trump White House Registers Aliens.gov—Is the UFO File Drop Imminent?

Trump White House Registers Aliens.gov—Is the UFO File Drop Imminent?

The post Trump White House Registers Aliens.gov—Is the UFO File Drop Imminent? appeared on BitcoinEthereumNews.com. In brief The White House registered aliens.gov
Share
BitcoinEthereumNews2026/03/19 05:33