Bitrefill Cyberattack Exposes 18,500 Records, Lazarus Group Suspected

TheNewsCryptoPublished on 2026-03-18Last updated on 2026-03-18

Abstract

Bitrefill, a cryptocurrency payment platform, was targeted by a cyberattack attributed to the North Korea-linked Lazarus Group on March 1, 2026. The breach, which began with a compromised employee laptop, exposed approximately 18,500 customer purchase records, including email addresses, crypto payment addresses, and IP data. The attackers primarily focused on moving funds from hot wallets and exploiting the gift card system, rather than stealing full customer data. Bitrefill quickly detected the unusual activity, shut down systems to prevent further damage, and has committed to covering all losses with its own funds. The company has since enhanced security measures, including stronger access controls and improved monitoring, and confirmed that most services are back to normal. This was Bitrefill's first major security breach in over a decade.

Bitrefill, a cryptocurrency payment platform, reported that it was the target of a cyberattack on March 1, 2026, and it attributed the attack to the Lazarus Group, a hacker collective associated with North Korea. The attack exposed about 18,500 customer purchase records and impacted several aspects of Bitrefill’s systems, including its cryptocurrency wallets.

How this Breach Happened

According to the firm, the breach began with the compromised employee’s laptop. In this case, the hackers were able to enter Bitrefill’s infrastructure and access production keys by moving funds from the hot wallet to exploit its gift card system. The company noticed unusual activity and quickly shut down systems to stop further damage.

The attacker accessed about 18,500 purchase records, which include email addresses, crypto payment addresses, and IP address data. The firm says that the hackers did not try to steal full customer data, and their main focus was on the crypto funds and the gift cards.

Bitrefill confirmed that it will cover all losses using its own funds. The company said it remains financially stable and that most services, including payments and accounts, are now back to normal.

Bitrefill has taken steps to improve security by providing stronger access control, better monitoring systems, external security testing, and faster response systems for future attacks. Additionally, it collaborates with blockchain analysts and security experts. According to Bitrefill, the hack was the company’s first significant security breach in more than ten years. Despite the attack’s damage, the business swiftly responded and resumed operations.

Highlighted Crypto News:

SEC and CFTC Introduce Crypto Classification Framework

TagsBitrefillCryptocurrency

Related Questions

QWhat company was targeted in the cyberattack and who is suspected to be behind it?

ABitrefill, a cryptocurrency payment platform, was targeted, and the attack is attributed to the Lazarus Group, a hacker collective associated with North Korea.

QHow many customer records were exposed in the Bitrefill breach?

AApproximately 18,500 customer purchase records were exposed.

QWhat type of information was accessed in the compromised purchase records?

AThe accessed information includes email addresses, crypto payment addresses, and IP address data.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe breach began with a compromised employee's laptop, which allowed the hackers to enter the infrastructure and access production keys.

QWhat steps has Bitrefill taken to improve its security following the attack?

ABitrefill has implemented stronger access control, better monitoring systems, external security testing, and faster response systems. It is also collaborating with blockchain analysts and security experts.

Related Reads

Bank of America Quietly Positions: Could $6 Trillion in Bank Deposits Flow into Stablecoins?

Bank of America has quietly made leadership appointments to accelerate its digital asset strategy, sparking discussion about a potential large-scale migration of bank deposits to stablecoins. Reports highlighted the bank naming Sonali Theisen, Kevin Milsom, and Adam Dixon to lead its global digital asset and AI platform, focusing on stablecoins, tokenized deposits, custody, and crypto settlement. This move revived a claim that $6 trillion in bank deposits could flow into stablecoins, a figure originally cited by Bank of America's CEO Brian Moynihan in January. However, he conditioned this shift on stablecoins being allowed to pay interest—a feature not permitted under the current GENIUS Act. The legislation's final rules are delayed, pushing its effective date to January 2027. Major banks are not waiting. JPMorgan and Citigroup are already piloting tokenized deposit services, and a consortium including Bank of America is building a shared tokenized deposit network targeting a 2027 launch. While some, like Pacemakers.io's Alessandro Hatami, remain skeptical of rapid bank collaboration, data shows significant institutional adoption. Stablecoin settlement volume hit $33 trillion in 2025, and analysts project the market could surpass $1 trillion by 2026. Despite a recent dip in crypto prices and stablecoin supply, the institutional push for real-world use cases continues. The race is on for January 2027, when the GENIUS Act takes effect, potentially reshaping the competition between traditional finance and digital assets.

Foresight News2m ago

Bank of America Quietly Positions: Could $6 Trillion in Bank Deposits Flow into Stablecoins?

Foresight News2m ago

US Treasury Secretary Bement Claims: The US Will Soon Control 80% of Global Computing Power

U.S. Treasury Secretary Ben Sent proclaimed that America is poised to control 80% of the world's computing power, positioning compute dominance as a core pillar of U.S. economic strategy. Speaking on the Mike Rowe show, he stated the U.S. currently holds 50-60% of global compute share, with expectations to reach 80% soon. He framed this as a strategic competition the U.S. "cannot afford to lose," warning that a rival's lead would grant "unacceptable" strategic leverage, while asserting a current one-year AI lead. This high-level policy endorsement is seen as a direct boost for AI infrastructure investment, benefiting chipmakers like NVIDIA and cloud providers' capex cycles. Sent positioned AI compute, semiconductors, and quantum computing as three pillars of national economic strength and security. He defended AI's societal impact, citing historical tech shifts, and argued AI empowers small businesses without causing net job loss so far. He highlighted government efforts to deepen public-private AI cybersecurity cooperation. For investors, the statement signals sustained U.S. policy support for AI infrastructure. However, analysts urge caution, noting "compute share" lacks a standard public metric; the 80% figure is a forecast, not audited data. They recommend focusing on tangible indicators like physical capacity expansion and power infrastructure, with future semiconductor and cloud reports providing key verification data.

marsbit13m ago

US Treasury Secretary Bement Claims: The US Will Soon Control 80% of Global Computing Power

marsbit13m ago

Trading

Spot
活动图片