Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoPublicado em 2026-03-17Última atualização em 2026-03-17

Resumo

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Perguntas relacionadas

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Leituras Relacionadas

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

Coldcard has urgently warned users to move their Bitcoin holdings, confirming on Tuesday that a vulnerability—which has already led to the theft of up to $114 million from self-custody wallets—remains actively exploited. The company stressed this is not a precautionary alert, citing a fourth wave of fraudulent transactions on Monday that drained approximately 449 BTC from 709 addresses. The flaw, dormant since 2021, involves firmware in cases where funds are controlled by a single key without a second confirmation. Users of Mk3 models (with firmware 4.0.1 or later) must transfer funds immediately. Owners of Mk4, Mk5, and Q models with firmware below 5.6.0 or 1.5.0Q should update firmware, generate a new wallet, then move coins. The vulnerability is tied to insufficient entropy during seed phrase generation, potentially allowing attackers to guess the key and drain wallets remotely. An exception is made for users who employed the device’s “dice roll” feature for key generation, as those wallets never touched the compromised code. Vincent Buzon, a cybersecurity expert at rival hardware wallet maker Ledger, noted the incident stemmed from an implementation failure, emphasizing that secure entropy generation must be hardware-based. He warned that software wallets on unprotected devices are riskier, and holding funds on centralized exchanges represents “not ownership, but an IOU.” Bitcoin traded around $63,800 in the U.S. on Tuesday, largely unaffected by the wallet warning.

cryptonews.ruHá 9m

Coldcard Urges Users to Move Bitcoin as Vulnerability Remains Exploited

cryptonews.ruHá 9m

Ethereum Price Forecast: Why Does ETH Remain Stable After Five Consecutive Weeks of ETF Inflows?

Ethereum Price Forecast: Why ETH Stays Stable After Five Consecutive Weeks of ETF Inflows? Ethereum (ETH) is trading around $1,867.68, showing little movement despite five consecutive weeks of net inflows into spot ETFs and a new community-dividing proposal, EIP-8363, that could significantly alter ETH's supply dynamics. Technically, ETH is consolidating between key support at $1,837.76 (0.382 Fibonacci) and resistance around $1,939. A descending trendline from May near $1,900 continues to cap price rallies. The MACD indicator remains bearish, suggesting sideways momentum persists until a breakout occurs. On August 4th, spot ETH ETFs saw a strong $53.75 million daily inflow, led by BlackRock's ETHA. This marks the fifth straight week of positive inflows, with total net inflows reaching $11.25 billion. A major talking point is EIP-8363, the "Tapered Issuance Burn" proposal backed by researchers like Justin Drake. It aims to burn an increasing share of validator rewards as the staked ETH ratio grows, reaching 100% burn when 60.25 million ETH (≈50% of supply) is staked. Proponents see it as a long-term positive supply shock for price. However, opponents warn it could disadvantage small validators and reduce staking yields, potentially dampening institutional demand. **Price Outlook:** * **Bull Case (Target: $2,042):** A daily close above the $1,940 resistance and the descending trendline, fueled by sustained ETF inflows and EIP-8363 supply narrative, could open a path toward the 0.618 Fibonacci level at $2,042. * **Bear Case (Risk to $1,711):** If selling pressure resumes, ETH losing the $1,837 support could lead to a decline toward the 0.236 Fibonacci level at $1,711, with June's low of $1,506 as a deeper risk level.

cryptonews.ruHá 13m

Ethereum Price Forecast: Why Does ETH Remain Stable After Five Consecutive Weeks of ETF Inflows?

cryptonews.ruHá 13m

Chainstack Adds Support for Robinhood Chain for Managed and Self-Hosted Nodes

Chainstack, a Web3 infrastructure platform supporting over 100,000 developers across 70+ blockchain networks, has added support for Robinhood Chain across its three deployment models: Global Nodes, Dedicated Nodes, and Chainstack Self-Hosted. The support is available for both the mainnet (chain ID 4663) and testnet (chain ID 46630). Robinhood Chain is an Ethereum L2 network built on Arbitrum Orbit with Nitro, optimized for financial and tokenized real-world asset transactions. It offers 100-millisecond block times and uses ETH for gas. A key feature is its first-come, first-served transaction ordering based on endpoint latency, making node placement a matter of execution rather than fee strategy. Chainstack's three models provide different levels of control and infrastructure: scalable Global Nodes for dApps and wallets, high-performance Dedicated Nodes with unlimited requests for marketplaces and protocols, and Self-Hosted Nodes for clients requiring full control over data sovereignty and deployment in their own environment. The Self-Hosted option is highlighted as critical for regulated issuers and brokers who cannot use third-party infrastructure due to compliance. The platform offers a unified management plane, billing, and monitoring for RWA workflows across multiple blockchains. Access is available immediately, with testnet tokens provided via a faucet and a free tier for evaluation.

cryptonews.ruHá 16m

Chainstack Adds Support for Robinhood Chain for Managed and Self-Hosted Nodes

cryptonews.ruHá 16m

Trading

Spot
活动图片