Published

Crypto02 April, 20263 min read

North Korea-linked Lazarus Group Breaches Bitrefill, Exposes 18,500 Purchase Records

This article is an automated aggregation of coverage from news outlets. Our editorials offer in-depth analysis curated by the NewsCord team.

Lazarus Group conducted March 1 cyberattack on Bitrefill, draining hot wallets. About 18,500 purchase records were exposed.

North Korea-linked Lazarus Group Breaches Bitrefill, Exposes 18,500 Purchase Records
Image: 01net

Attack Overview

Cryptocurrency e-commerce platform Bitrefill fell victim to a significant cyberattack on March 1, 2026. North Korea-linked Lazarus Group hackers compromised its infrastructure, drained cryptocurrency hot wallets, and exposed approximately 18,500 purchase records containing sensitive customer information. The breach represents another major incident attributed to the notorious Lazarus Group, which has been linked to some of the largest cryptocurrency thefts in recent history.

“Bitrefill said a March 1, 2026 cyberattack linked to North Korea's Lazarus Group compromised parts of its infrastructure, drained some hot wallets and exposed about 18,500 purchase records.”
CoinDesk

This includes a heist exceeding $1 billion from Bybit the previous year. Bitrefill, a platform designed to enable cryptocurrency users to purchase digital gift cards and pay bills online through partnerships with major retailers like Amazon, Apple, Walmart, and Uber, confirmed the incident. The company emphasized that customer balances remain safe despite the attack.

Image from @coindesk
Image: @coindesk

Attack Vector

The attack originated from a compromised employee laptop that contained legacy credentials, allowing attackers to access production keys and escalate privileges across Bitrefill's infrastructure. According to the company's incident report, the breach began when hackers recovered credentials from the laptop that provided access to sensitive production data snapshots. Once inside, the attackers systematically moved deeper into Bitrefill's systems, targeting both its internal database segments and cryptocurrency hot wallets.

The intruders also exploited the company's gift card inventory systems, making fraudulent purchases with vendors through compromised supply chain channels. This sophisticated attack pattern suggests a well-planned operation designed to maximize financial gain while minimizing detection.

Data Exposure

The breach exposed sensitive data from approximately 18,500 purchase records, including email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. Among these records, around 1,000 contained customer names in encrypted form, which Bitrefill is treating as potentially exposed due to the possibility that attackers may have obtained the corresponding encryption keys. Despite the significant data exposure, Bitrefill maintains that it stores minimal personal data and does not require mandatory know-your-customer verification for most transactions.

“The attackers gained access to production keys, transferred funds from hot wallets, and exposed 18,500 purchase records containing emails, payment addresses, and IP addresses.”
CoinDesk

The company clarified that any KYC-related information is handled by external providers and not stored within Bitrefill's systems, reducing the overall risk to customer privacy. The investigation found no evidence that the attackers accessed Bitrefill's full database or that customer data was their primary objective.

Response & Impact

In response to the security breach, Bitrefill immediately took its systems offline to contain the breach across its global operations, with services remaining unavailable for approximately four days while the company worked to address the incident. The company collaborated extensively with external security researchers, including specialized incident response firms like zeroShadow, SEAL911, and RecoverisTeam, as well as blockchain analysts and law enforcement to investigate the breach. Despite the significant disruption, Bitrefill has since restored most services to normal levels, including payment processing and account access.

The company has committed to covering all financial losses from the attack using its operational capital, though it did not disclose the exact amount stolen from the hot wallets. This incident highlights the ongoing challenges in cryptocurrency security and the need for stronger supply-chain and penetration testing defenses across the ecosystem.

Attribution

Bitrefill attributed the attack to North Korea's Lazarus Group based on multiple indicators including similarities in malware patterns, reused infrastructure such as IP addresses and email accounts, and on-chain transaction analysis. While the company did not present this attribution as definitively confirmed, citing the sophisticated nature of the attack, multiple cybersecurity firms including zeroShadow, SEAL911, and RecoverisTeam supported the investigation. The Lazarus Group, often associated with North Korea, has been responsible for numerous high-profile cryptocurrency heists through its specialized subgroup Bluenoroff.

“Bitrefill cited several indicators linking the attack to the Lazarus Group, including similarities in malware, reused infrastructure such as IP addresses and email accounts, and on-chain transaction patterns. The group, often associated with North Korea, has been tied to some of the largest crypto thefts in recent years through its specialized subgroup, Bluenoroff.”
Bitcoin Magazine

This latest attack continues the group's pattern of targeting cryptocurrency platforms and exchanges, demonstrating their continued capability and focus on financial cyber operations. The incident serves as a stark reminder of the persistent threat posed by state-sponsored hacking groups in the cryptocurrency ecosystem.