Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoPublished on 2026-03-17Last updated on 2026-03-17

Abstract

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Related Questions

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Related Reads

Has the Crypto Market Bottomed? Here's What Institutions Think

The crypto market is in a period of significant debate, with leading institutions offering differing views on whether a bottom has been reached. Three prominent firms have published detailed analyses: * **Galaxy Digital** argues Bitcoin has **not yet bottomed**. Their analysis of 13 historical indicators across six dimensions (valuation, profit-taking, miner pressure, etc.) shows only four are fully met. They project a potential bottom range between $30k and $54k. * **NYDIG** states a bottom is **possible but not likely**. While metrics are close to historic bear market extremes, they note the absence of a classic panic-selling event. They also suggest increased institutional adoption may have structurally altered the market cycle, potentially leading to a shallower downturn. * **Standard Chartered Bank** asserts the **bottom has already occurred** at around $59k. They cite two key factors: potential US-Iran diplomatic progress and the anticipated SpaceX IPO, which they believe absorbed capital and caused ETF selling pressure that is now subsiding. They forecast a year-end price target of $100k. Despite the surface-level disagreement, the reports share critical common ground more valuable for long-term investors: 1. All three believe the market bottom will form **within this year**. 2. All agree the current price is **closer to the bottom than to previous highs**. 3. All maintain a **bullish long-term outlook** for Bitcoin and a new cycle. The core takeaway is that while the exact bottom price ($40k, $50k, or $60k) is debated, the consensus is that a bottom is imminent. For long-term holders, the primary focus should not be pinpointing the absolute low, but on the future potential for prices to reach $100k, $200k, or higher. The fundamental thesis for Bitcoin—sovereign debt accumulation, inflation, declining trust in centralized institutions, global digitization, and improved accessibility—remains intact and is arguably strengthening. The overall landscape is viewed as more favorable than in previous crypto winters.

marsbit9m ago

Has the Crypto Market Bottomed? Here's What Institutions Think

marsbit9m ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

China's Photonics Industry: Bottlenecks and Breakthroughs In the global AI race, computing chips dominate the narrative, but the underlying bottleneck increasingly defining the scale of AI clusters is light—or more specifically, optical connectivity. Optical modules, which translate electrical signals to light and vice versa, are crucial for connecting thousands of GPUs in AI data centers, preventing data congestion and ensuring efficient model training. High-speed modules (800G, 1.6T) are now standard, with performance hinging on advanced DSP (Digital Signal Processor) chips. This is where a critical dependency lies. Two US giants—Marvell and Broadcom—collectively dominate over 90% of the high-end DSP chip market. Chinese optical module leaders like Zhongji Innolight and Eoptolink rely on these chips to manufacture modules for overseas AI customers, primarily in North America. While this creates a supply chain vulnerability, complete decoupling is difficult. Marvell derives over half its revenue from Greater China, and the US firms depend on Chinese partners for chip packaging and optical components. The risk from laser chips (e.g., from Lumentum), another key component, is considered more manageable due to multiple global suppliers and faster progress in domestic alternatives from companies like YOFC and Accelink. To mitigate risks, China's industry is pursuing a multi-pronged strategy: diversifying supply chains and locking in long-term orders; fostering a domestic market ecosystem to adopt homegrown DSPs from firms like Huawei HiSilicon and CETC; accelerating R&D in high-speed DSPs and advanced packaging; and investing in next-gen technologies like silicon photonics and Co-Packaged Optics (CPO) to reduce reliance on discrete DSPs. The ultimate solution lies not in short-term博弈 but in persistent advancement of domestic high-end chip R&D and manufacturing. While challenges remain in performance, certification, and ecosystem building, China's vast domestic market and manufacturing base provide a crucial buffer, buying time for the industry to achieve greater technological independence.

marsbit22m ago

The 'Chip' Challenge and Breakthroughs in China's Optical Industry Chain

marsbit22m ago

Behind SpaceX's $2 Trillion Market Cap: Why Does Musk Always Have the Next Move Planned?

On June 12th, SpaceX debuted on the Nasdaq, reaching a valuation that briefly touched $2 trillion. This marked the culmination of a 24-year journey from its founding in 2002, driven by Elon Musk's frustration at the high cost of buying rockets. The company's path was defined by early failures, with its first three Falcon 1 launches ending in explosions before a successful 2008 flight opened the era of commercial spaceflight. Key to its model was a fixed-price NASA contract, incentivizing cost reduction. SpaceX mastered rocket reusability, first achieving a Falcon 9 landing in 2015, which drastically cut launch costs. This enabled its profitable Starlink satellite internet constellation, envisioned years before reusability was proven, to create an internal market for frequent launches. Similarly, the next-generation Starship rocket was in development long before its first flight, with its business case evolving from Mars colonization to supporting the emerging concept of in-orbit data centers for AI—a story now central to its valuation. The company's recent IPO, a reversal of its long-standing "no IPO" stance, is funding this ambitious "space-based compute" vision. While major tech players like Google, Blue Origin, and others are investing heavily, significant technical and cost hurdles remain. Ultimately, SpaceX's history is one of creating its own demand: first with Starlink and now with space-based AI compute, betting that its next rocket will enable its next giant market.

marsbit25m ago

Behind SpaceX's $2 Trillion Market Cap: Why Does Musk Always Have the Next Move Planned?

marsbit25m ago

When Crypto Meets the World Cup: CoinW and Modrić's Art of "Navigating Cycles"

When Encryption Meets the World Cup: CoinW and Modrić's "Transcending Cycles" Philosophy In the context of the 2026 FIFA World Cup and its massive global audience, the crypto exchange CoinW announced football legend Luka Modrić as its global brand ambassador. This move is framed not merely as a marketing tactic, but as a strategic experiment in user profile migration. It targets mature, financially stable football fans—particularly in Europe, Southeast Asia, and Latin America—who traditionally have low crypto awareness but value trusted, time-tested authority figures like Modrić. The article draws parallels between Modrić's enduring, disciplined career—marked by consistency and success at the highest level over two decades—and CoinW's own development path. Founded in 2017 during a volatile industry period, CoinW focused on building robust infrastructure and risk management. It weathered the 2022 industry crisis without major security incidents, subsequently earning recognition like "Europe's Most Trusted Exchange" and growing to over 20 million registered users. This "long-termism" is translated into user-centric products. CoinW Academy lowers the initial knowledge barrier. Its integrated ecosystem (CoinW, GemW, DeriW, PropW) and the recent launch of a TradFi section—offering perpetual contracts on traditional assets like stocks, gold, and oil—aim to create a unified platform for diverse assets. For the World Cup, CoinW launched the "We Are The Game" campaign, collaborating with Alchemy Pay to offer zero-fee deposits and local payment options, aiming to transform spectators into participants and lower entry barriers. Ultimately, CoinW's sports partnerships and product strategy are presented as a concerted effort to build trust and accessibility for the "silent majority" still outside crypto—shifting the industry narrative toward inclusivity and long-term value.

Foresight News31m ago

When Crypto Meets the World Cup: CoinW and Modrić's Art of "Navigating Cycles"

Foresight News31m ago

Trading

Spot
Futures
活动图片