Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoPublié le 2026-03-17Dernière mise à jour le 2026-03-17

Résumé

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Questions liées

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Lectures associées

Bitwise CIO : Qu'arrivera-t-il au marché crypto si le projet de loi CLARITY échoue cette semaine ?

Matt Hougan, CIO de Bitwise, analyse les conséquences potentielles pour le marché crypto si le projet de loi CLARITY, une législation américaine cruciale pour l'industrie, échouait cette semaine au Sénat. Bien qu'une adoption déclencherait probablement un nouveau marché haussier, son rejet est considéré comme plus probable. Dans ce scénario, le projet entrerait dans un état « zombie », avec des tentatives potentielles pour le faire passer plus tard dans l'année via d'autres moyens législatifs. Cette incertitude prolongée pourrait maintenir certains investisseurs institutionnels en retrait à court terme. Cependant, Hougan souligne que l'industrie elle-même continuera d'avancer. Le président de la SEC, Paul Atkins, a indiqué que l'agence est prête à mettre en œuvre des règles réglementaires similaires, potentiellement plus favorables à court terme. L'élan du secteur est jugé irréversible : adoption des ETF Bitcoin par des géants comme BlackRock, développement de la tokenisation par des institutions financières majeures, et intégration croissante des entreprises crypto dans le système bancaire américain. En s'appuyant sur l'exemple historique du retard de la loi sur les télécommunications de 1996, qui n'a pas empêché l'explosion d'Internet, l'auteur conclut que Washington est souvent en retard sur l'innovation technologique. Quel que soit le résultat immédiat au Congrès, la crypto, désormais partie intégrante de l'infrastructure financière mondiale, est destinée à remodeler le système financier pour les décennies à venir.

marsbitIl y a 2 h

Bitwise CIO : Qu'arrivera-t-il au marché crypto si le projet de loi CLARITY échoue cette semaine ?

marsbitIl y a 2 h

L'Allemagne a perdu sa première place après des décennies, tandis que la Chine devient discrètement le leader mondial des machines-outils

L'industrie chinoise des machines-outils a réalisé une percée significative en 2025, dépassant pour la première fois l'Allemagne en valeur d'exportation avec 8,6 milliards d'euros et 21% de part de marché mondial. Cette ascension marque un tournant pour un secteur longtemps perçu comme dépendant des importations de machines allemandes ou japonaises, coûteuses et soumises à des restrictions. Le chemin fut long et ardu. La fabrication de machines-outils de précision se heurte à des défis physiques majeurs : la gestion de la dilatation thermique, les vibrations en cours d'usinage et l'usure des composants critiques, qui affectent la précision et la durabilité. Le secteur chinois était historiquement faible sur ces points, avec un taux de défaillance initial très élevé et une forte dépendance aux importations pour les composants clés (systèmes de commande numérique, broches, vis à billes). Le virage a été amorcé par le "Projet spécial 04" (2009-2020), un programme national qui a relevé la fiabilité des machines et accru la part des systèmes CNC nationaux. L'essor fulgurant de secteurs comme les véhicules électriques a ensuite fourni un marché exigeant et en rapide évolution, permettant aux fabricants chinois de développer des solutions sur mesure (centres d'usinage pour grandes pièces moulées, équipements pour boîtiers de batteries). Cependant, cette première place à l'exportation, principalement portée par les machines de découpe spéciale (laser, EDM) et vers des marchés asiatiques, ne signifie pas une supériorité technique globale. Des écarts persistent dans les machines haut de gamme et les composants de précision. Le véritable défi désormais est de construire une réputation de fiabilité à long terme et un réseau de service après-vente mondial capable d'instaurer une confiance durable chez les clients internationaux. La transition de l'industrie chinoise, d'acheteuse contrainte à exportatrice responsable, est en cours, mais sa consolidation définitive se jouera sur la capacité de ses machines à garantir une précision stable pendant des années dans les usines du monde entier.

marsbitIl y a 2 h

L'Allemagne a perdu sa première place après des décennies, tandis que la Chine devient discrètement le leader mondial des machines-outils

marsbitIl y a 2 h

Trading

Spot
活动图片