Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoDipublikasikan tanggal 2026-03-17Terakhir diperbarui pada 2026-03-17

Abstrak

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Pertanyaan Terkait

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Bacaan Terkait

Keranjang yang Lebih Besar dari Robinhood

Beberapa minggu lalu, Robinhood digambarkan sebagai "supermarket keuangan" yang memenuhi berbagai kebutuhan finansial dalam satu platform. Laporan keuangan Q2 2026 menunjukkan perusahaan ini berkembang pesat bukan dengan menarik lebih banyak pengguna baru, tetapi dengan mendorong pengguna yang ada untuk menggunakan lebih banyak produk, lebih sering, dan dengan nilai transaksi yang lebih tinggi. Hal ini tercermin dari peningkatan Average Revenue Per User (ARPU) sebesar 24%, jauh melampaui pertumbuhan jumlah pengguna. Kunci kesuksesannya terletak pada kemampuan cross-selling yang kuat, didorong oleh layanan langganan Robinhood Gold. Sekitar 40-50% pelanggan baru mendaftar ke Gold, yang kemudian meningkatkan penggunaan produk lain seperti pensiun (IRA) dan aset yang dikelola. Dua katalis utama untuk pertumbuhan di masa depan adalah Robinhood Chain (blockchain native) dan Robinhood Social (feed sosial internal). Chain memungkinkan komposisi produk seperti token saham, pinjaman, dan futures secara mulus, sementara Social menginternalisasi proses pencarian ide investasi, membangun kepercayaan melalui portofolio yang terverifikasi. Dengan lebih dari 13 lini bisnis yang masing-masing menghasilkan pendapatan tahunan berulang lebih dari $100 juta, model bisnis Robinhood menjadi semakin tahan terhadap siklus pasar. Diversifikasi pendapatan dari banyak produk ke satu pengguna membuat pendapatan perusahaan lebih stabil. Robinhood tidak hanya menawarkan banyak layanan, tetapi menciptakan ekosistem di mana setiap hubungan pelanggan menjadi simpul pendapatan yang terdiversifikasi dan dapat berkembang pesat.

marsbit2j yang lalu

Keranjang yang Lebih Besar dari Robinhood

marsbit2j yang lalu

Peringkat Pertama Jerman yang Bertahan Puluhan Tahun Tergeser, Mesin Perkakas China Diam-diam Menjadi Nomor Satu di Dunia

Cerita kebangkitan manufaktur China terus didengar: produksi mobil listrik nomor satu global, komponen fotovoltaik tersebar ke separuh dunia, kereta cepat hingga Indonesia, peralatan rumah tangga dan mainan China digunakan di seluruh dunia. Namun, ada satu bidang yang masih dikejar: mesin perkakas. Mesin perkakas adalah peralatan dasar manufaktur modern, menentukan seberapa presisi komponen yang dapat diproduksi. Dulu, mesin China identik dengan impor mahal dari Jerman dan Jepang, dengan banyak pembatasan. Tetapi pada 2025, ekspor mesin China mencapai 8,6 miliar euro, menggeser Jerman sebagai eksportir terbesar dunia dengan pangsa 21%. Prestasi ini adalah hasil perjalanan panjang. Awalnya, sistem kontrol numerik (CNC) kelas atas China memiliki tingkat kegagalan tinggi. Program nasional "04 Special Project" (2009-2020) berhasil meningkatkan penggunaan sistem CNC domestik dari kurang dari 1% menjadi 31,9% dan memperpanjang waktu operasi bebas gangguan. Pasar domestik yang masif, terutama ledakan kendaraan listrik (EV), menjadi pendorong kuat. EV memperkenalkan kebutuhan baru seperti pengecoran integral bodi mobil besar dan pemrosesan casing baterai, menciptakan peluang bagi produsen lokal yang dapat berinovasi cepat dan bekerja sama erat dengan pelanggan di dekat mereka. Ekspor kini menjadi sumber pertumbuhan utama. Namun, keunggulan saat ini terutama pada skala dan cakupan, khususnya di mesin pemotong khusus seperti EDM dan laser. Tujuan ekspor terbesar adalah Vietnam, Rusia, India, Thailand, dan AS. Meski angka ekspor mengesankan, tantangan tetap ada. Tingkat adopsi di segmen mesin paling presisi, seperti mesin gerinda untuk komponen mobil, masih di bawah 10%. Selain itu, membangun jaringan layanan purna jual global yang andal sama pentingnya dengan menjual mesin. Kepercayaan pelanggan internasional akan benar-benar terbentuk ketika mereka bersedia mempercayakan lini produksi mereka selama satu dekade ke mesin berlabel "Made in China". Menjadi nomor satu dalam ekspor hanyalah awal; langkah selanjutnya adalah mengonsolidasikan posisi ini melalui keandalan, presisi jangka panjang, dan dukungan layanan di seluruh dunia.

marsbit2j yang lalu

Peringkat Pertama Jerman yang Bertahan Puluhan Tahun Tergeser, Mesin Perkakas China Diam-diam Menjadi Nomor Satu di Dunia

marsbit2j yang lalu

Trading

Spot
活动图片