Crypto gift card and e-commerce platform Bitrefill has published a detailed post-mortem disclosing a cyberattack that began on March 1, 2026, exposing approximatelyCrypto gift card and e-commerce platform Bitrefill has published a detailed post-mortem disclosing a cyberattack that began on March 1, 2026, exposing approximately

Crypto Platform Confirms North Korea Hacked Its Systems

2026/03/18 19:31
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto gift card and e-commerce platform Bitrefill has published a detailed post-mortem disclosing a cyberattack that began on March 1, 2026, exposing approximately 18,500 purchase records and draining several company hot wallets.

In X post from its official account, the company attributed the attack to the Lazarus Group, a state-sponsored hacking collective linked to North Korea, or its financial crime subgroup Bluenoroff.

What Was Exposed

The compromised records contained a limited range of customer data including email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. Around 1,000 of the affected records also included customer names. While that data was stored in encrypted form, Bitrefill is treating it as potentially compromised on the basis that the attackers may have obtained access to the relevant encryption keys during the intrusion.

Bitrefill was explicit that no mandatory KYC data was taken. The company does not store that information on its internal systems, instead managing it through an external provider that was not affected by the breach. For the majority of affected users, the exposure is limited to transactional metadata rather than identity documents or financial verification records.

How the Attack Unfolded

The intrusion began with a compromised employee laptop. From that initial access point, the attackers extracted what Bitrefill described as a legacy credential, an older set of access keys that had not been fully decommissioned. Using those credentials, the attackers accessed a system snapshot containing production secrets, which gave them the foothold needed to move through Bitrefill’s broader infrastructure and reach its database systems.

Once inside, the attackers drained several company hot wallets and placed suspicious orders through Bitrefill’s gift card suppliers, suggesting a deliberate attempt to convert stolen access into liquid value through the platform’s own supply chain.

Bitrefill linked the attack to Lazarus Group based on specific indicators of compromise identified during the forensic investigation. These included the malware used in the intrusion, the reuse of IP addresses and email addresses previously associated with North Korean hacking operations, and on-chain tracing of the stolen funds to wallets connected to prior Lazarus activity.

US Spot Crypto ETFs Pull in $361 Million in a Single Day as Institutional Appetite Grows

Response and Recovery

Bitrefill took its systems offline shortly after detecting the breach and kept them down for over two weeks while it contained the threat and assessed the full scope of the damage. The company confirmed on March 17 that almost all services, including payments, user accounts, and product stock, had been restored to normal operation.

The company stated it will fully absorb all financial losses from its own operational capital. User balances were not affected by the breach and remain intact.

Bitrefill is currently working with cybersecurity firms zeroShadow and SEAL911 to implement tighter internal access controls and enhanced monitoring across its infrastructure. The company identified the legacy credential and the unrotated system snapshot as the two critical failure points that allowed the attack to escalate from a single compromised device to full infrastructure access.

Broader Context

The Lazarus Group has been one of the most active and destructive threat actors in the crypto space for several years. The group has been linked to billions of dollars in stolen cryptocurrency across dozens of incidents, with proceeds reportedly used to fund North Korea’s weapons programs. Targeting a mid-sized crypto commerce platform rather than a major exchange reflects a broader pattern in which the group pursues a high volume of smaller targets alongside its more prominent attacks.

For Bitrefill users, the immediate risk from this specific breach is relatively contained given the absence of KYC data. The more significant takeaway is how a single unmanaged credential on a compromised laptop was sufficient to give sophisticated state-level attackers a path through an entire company’s infrastructure.

The post Crypto Platform Confirms North Korea Hacked Its Systems appeared first on ETHNews.

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0002908
$0.0002908$0.0002908
-2.61%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Let insiders trade – Blockworks

Let insiders trade – Blockworks

The post Let insiders trade – Blockworks appeared on BitcoinEthereumNews.com. This is a segment from The Breakdown newsletter. To read more editions, subscribe ​​“The most valuable commodity I know of is information.” — Gordon Gekko, Wall Street Ten months ago, FBI agents raided Shayne Coplan’s Manhattan apartment, ostensibly in search of evidence that the prediction market he founded, Polymarket, had illegally allowed US residents to place bets on the US election. Two weeks ago, the CFTC gave Polymarket the green light to allow those very same US residents to place bets on whatever they like. This is quite the turn of events — and it’s not just about elections or politics. With its US government seal of approval in hand, Polymarket is reportedly raising capital at a valuation of $9 billion — a reflection of the growing belief that prediction markets will be used for much more than betting on elections once every four years. Instead, proponents say prediction markets can provide a real service to the world by providing it with better information about nearly everything. I think they might, too — but only if insiders are free to participate. Yesterday, for example, Polymarket announced new betting markets on company earnings reports, with a promise that it would improve the information that investors have to work with.  Instead of waiting three months to find out how a company is faring, investors could simply watch the odds on Polymarket.  If the probability of an earnings beat is rising, for example, investors would know at a glance that things are going well. But that will only happen if enough of the people betting actually know how things are going. Relying on the wisdom of crowds to magically discern how a business is doing won’t add much incremental knowledge to the world; everyone’s guesses are unlikely to average out to the truth. If…
Share
BitcoinEthereumNews2025/09/18 05:16
T7X Launches Regulated Launchpad for Tokenized Real-World Asset Securities

T7X Launches Regulated Launchpad for Tokenized Real-World Asset Securities

SHERIDAN, Wyo., March  18, 2026  (GLOBE NEWSWIRE) -- T7X announces the launch of the T7X Launchpad, a digital issuance platform designed to support the crea
Share
CryptoReporter2026/03/18 20:49
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41