The post Bitrefill Cyberattack Linked to North Korea’s Lazarus Group, Exposes 18,500 Customer Records appeared on BitcoinEthereumNews.com. TLDR: Bitrefill’s MarchThe post Bitrefill Cyberattack Linked to North Korea’s Lazarus Group, Exposes 18,500 Customer Records appeared on BitcoinEthereumNews.com. TLDR: Bitrefill’s March

Bitrefill Cyberattack Linked to North Korea’s Lazarus Group, Exposes 18,500 Customer Records

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR:

  • Bitrefill’s March 2026 breach was linked to North Korea’s Lazarus Group based on malware and IP patterns.
  • Attackers used a stolen legacy credential from an employee laptop to access production infrastructure. 
  • Around 18,500 purchase records were accessed, exposing emails, crypto addresses, and IP metadata.
  • Bitrefill confirmed it remains financially stable, absorbing all losses through its operational capital.

Bitrefill, a global crypto payments platform, disclosed a cyberattack that took place on March 1, 2026. The attack is suspected to involve North Korea’s Lazarus Group, also known as Bluenoroff.

Approximately 18,500 purchase records were accessed, containing email addresses, crypto payment addresses, and IP metadata.

The company went public with the incident after a detailed investigation involving external security experts and law enforcement agencies.

How the Bitrefill Attack Was Carried Out

The breach started on a compromised employee laptop within the company’s network. Attackers extracted a legacy credential from that device without triggering immediate alerts. That credential gave them access to a snapshot holding production secrets.

Using those secrets, the attackers escalated access into Bitrefill’s broader infrastructure. They reached parts of the company’s database and specific cryptocurrency hot wallets. Funds were then moved to attacker-controlled wallets.

The platform detected the breach after noticing suspicious purchasing patterns with certain suppliers. The team found that gift card stock and supply lines were being exploited simultaneously. Several hot wallets were also being drained in real time.

On March 1, Bitrefill’s official account posted a full incident report on social media. The company confirmed taking all systems offline as soon as the breach was detected. Restoring services across dozens of suppliers and payment methods required careful coordination.

Security investigators found strong similarities between this attack and prior DPRK Lazarus Group operations. The malware deployed, on-chain tracing, and reused IP addresses all matched known patterns. The team collaborated with ZeroShadow, SEAL_Org, Recoveris, and other incident response specialists throughout the process.

What Happened to Customer Data and What Bitrefill Is Doing

Customer data was not the primary target in the Bitrefill breach. Logs showed the attackers ran only a limited number of queries during the intrusion. Those queries were focused on probing cryptocurrency and gift card inventory, not personal records.

Around 18,500 purchase records were accessed during the attack. Those records included email addresses, crypto payment addresses, and IP metadata. For roughly 1,000 purchases, names stored in encrypted form may also have been accessed.

Since the attackers potentially obtained the encryption keys, the company treated that name data as compromised. Bitrefill directly notified all affected customers by email. No specific action is currently required from the broader customer base.

As a precaution, Bitrefill advised customers to stay alert to unexpected communications related to the platform. The company stated it will notify affected users if the risk assessment changes. Transparency remained a central part of its public response throughout the ordeal.

The company confirmed it remains financially stable and has been profitable for several years. All losses were covered using operational capital, with no disruption to ongoing services. Sales volumes and payment processing have since returned to normal.

The post Bitrefill Cyberattack Linked to North Korea’s Lazarus Group, Exposes 18,500 Customer Records appeared first on Blockonomi.

Source: https://blockonomi.com/bitrefill-cyberattack-linked-to-north-koreas-lazarus-group-exposes-18500-customer-records/

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0003046
$0.0003046$0.0003046
-7.10%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Royal Government of Bhutan Moves 973 BTC in Latest Treasury Activity

Royal Government of Bhutan Moves 973 BTC in Latest Treasury Activity

The post Royal Government of Bhutan Moves 973 BTC in Latest Treasury Activity appeared on BitcoinEthereumNews.com. The Royal Government of Bhutan transferred 973
Share
BitcoinEthereumNews2026/03/18 19:29
Bubblemaps: The top five traders in STBL token trading volume are interconnected and have made profits exceeding $10 million

Bubblemaps: The top five traders in STBL token trading volume are interconnected and have made profits exceeding $10 million

PANews reported on September 18th that blockchain analytics platform Bubblemaps published an article on the X platform claiming that Tether co-founder Reeve Collins had just launched a new token, STBL. However, the top five traders are suspiciously interconnected and have profited over $10 million. Collins launched STBL yesterday, a new stablecoin system built around three tokens: USST (stablecoin), YLD (yield token supporting USST), and STBL (governance token). An analysis of the top five traders by STBL trading volume revealed that these five profit-makers received capital injections at the same time. Tracing the source of their funds revealed a clear connection: the funds all came from the same source (injected via Tornado Cash); bots were used to borrow USDC from the Venus Protocol; and the total profit exceeded $10 million. However, there is no evidence that these traders are connected to the core team. In fact, this group of bots has a history of extracting value from other tokens, not just STBL.
Share
PANews2025/09/18 10:09
Coinbase Vs. State Regulators: Crypto Exchange Fights Legal Fragmentation

Coinbase Vs. State Regulators: Crypto Exchange Fights Legal Fragmentation

US-based crypto exchange Coinbase has made a significant appeal to the Department of Justice (DOJ) regarding a wave of lawsuits aimed at its operations. The company is urging federal action to address what it describes as an “increasingly fragmented and hostile” regulatory landscape for the crypto market. Coinbase Urges Federal Action  In a recent letter, Coinbase highlighted the steps taken by the current Administration to create a more equitable framework for digital asset regulation. This includes the introduction of stablecoin legislation and two pending bipartisan market-structure bills aimed at fostering uniformity in the oversight of cryptocurrencies.  Coinbase argues that these initiatives have begun to mitigate the adverse effects of the previous Administration’s enforcement-driven regulatory approach.  However, the company warns that certain states are perpetuating this problematic trend by adopting “expansive and flawed” interpretations of securities laws and implementing new licensing requirements that undermine the federal government’s pro-innovation stance. Related Reading: REX Shares Claims Its DOGE And XRP Spot ETFs Will Be Approved By US SEC Tomorrow They make an example with the Oregon Attorney General, who has filed a lawsuit against Coinbase, claiming that many digital assets traded on its platform qualify as alleged unregistered securities.  The letter affirms that the suit not only targets Coinbase but also encourages other states to address what the Attorney General perceives as a regulatory gap left by federal authorities.  Similarly, the New York Attorney General has initiated legal action to regulate transactions involving digital assets based on decentralized protocols as securities, further complicating the regulatory environment. Coinbase has faced cease-and-desist orders from four states, which demand the company halt its retail staking services. These orders are deemed by Coinbase as “legally unfounded and inconsistent.” Unified Framework For Digital Assets In light of these challenges, the letter to the DOJ calls for urgent federal intervention to establish broad preemption provisions. The crypto exchange argues that preemption has historically been an effective tool for addressing state interference in national markets, referencing past Congressional actions. Coinbase contends that the current patchwork of state regulations not only disrupts market efficiency but also leads to unequal access to cryptocurrency services based on geographic location. Related Reading: Citi’s Ethereum Forecast: No New All-Time High Expected, Year-End Target At $4,300 To remedy these issues, Coinbase advocates for Congress to adopt legislation that would exempt federally regulated digital assets from state blue-sky laws and clarify that state licensing requirements do not apply to crypto intermediaries.  Additionally, the company urges the SEC to expedite rulemaking and provide clearer guidance on why digital asset transactions and services, including staking, should not be classified as securities. Such clarity would help prevent states from imposing conflicting regulations based on their interpretations of securities laws. Featured image from Shutterstock, chart from TradingView.com
Share
NewsBTC2025/09/18 15:00