Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoОпубликовано 2026-03-17Обновлено 2026-03-17

Введение

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Связанные с этим вопросы

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Похожее

Эксперты зафиксировали потенциальную продажу 1030 BTC компанией Strategy

Эксперты Lookonchain зафиксировали возможную продажу 1030 биткоинов корпорацией Strategy, крупнейшим корпоративным держателем BTC. Данные с платформы Arkham Intelligence свидетельствуют о переводе этой суммы с аффилированного кошелька несколькими траншами в ночь на 5 августа 2026 года. Назначение переводов (ребалансировка или внебиржевая продажа) не подтверждено, так как счета получателей не маркированы. Компания Strategy и ее сооснователь Майкл Сэйлор не прокомментировали информацию, и сделка не отражена на портале Saylor Tracker. Ранее Strategy уже продала в общей сложности 5258 BTC (примерно на $335 млн). Сэйлор пояснил, что компания никогда не давала обязательств не продавать криптоактивы, а его личная позиция по удержанию BTC не отражает корпоративную стратегию. Вырученные от продажи биткоинов средства направляются на обратный выкуп акций и выплату дивидендов по ценным бумагам STRC. Компания ставит своей приоритетной задачей возврат курса этих акций до номинала в $100.

cryptonews.ru8 мин. назад

Эксперты зафиксировали потенциальную продажу 1030 BTC компанией Strategy

cryptonews.ru8 мин. назад

Компания Coldcard призывает пользователей перевести биткоины, поскольку уязвимость все еще эксплуатируется

Разработчики аппаратного кошелька Coldcard срочно призвали пользователей перевести свои биткоины, подтвердив, что уязвимость, позволившая злоумышленникам вывести до $114 млн, остается активной. Риск касается владельцев моделей Mk3 (с прошивкой 4.0.1+) и Mk4/Mk5/Q (с прошивкой ниже 5.6.0/1.5.0Q). Им необходимо вручную обновить прошивку, создать новую сид-фразу и перевести средства. Исключение составляют пользователи, применявшие функцию «броска кубиков» для генерации ключа, так как их кошельки не затрагивает уязвимость. Проблема, существовавшая с 2021 года, связана с недостаточной энтропией в генерации сид-фразы в определенных условиях, что позволяет злоумышленникам угадать ключ. Эксперты подчеркивают критическую важность надежной аппаратной генерации энтропии для безопасности средств.

cryptonews.ru8 мин. назад

Компания Coldcard призывает пользователей перевести биткоины, поскольку уязвимость все еще эксплуатируется

cryptonews.ru8 мин. назад

Прогноз цены Ethereum: почему ETH остаётся стабильным после пяти недель подряд притоков ETF?

Аналитики отмечают, что цена Ethereum ($ETH) остается стабильной в районе $1 867, несмотря на пять недель подряд притока средств в спотовые ETF и новое предложение EIP-8363, которое может значительно сократить эмиссию монеты. Технический анализ показывает, что ETH торгуется в диапазоне между ключевой поддержкой на уровне $1 837 и сопротивлением $1 939, удерживая уровень 0.382 Фибоначчи. Пятая неделя притока в ETF и предложение «Сжигания с коническим выпуском», направленное на сокращение наград валидаторов, обсуждаются как долгосрочные бычьи катализаторы. Однако нисходящий тренд и неопределенность вокруг EIP-8363, которая может негативно повлиять на мелких стейкеров, ограничивают рост. Ближайшие бычьи цели находятся на уровне $2 042, в то время как потеря поддержки $1 837 может привести к падению к $1 711.

cryptonews.ru12 мин. назад

Прогноз цены Ethereum: почему ETH остаётся стабильным после пяти недель подряд притоков ETF?

cryptonews.ru12 мин. назад

Сможет ли цена Ethereum преодолеть отметку в 2000 долларов? Обсуждения по поводу EIP-8361 продолжаются

Курс Ethereum ($ETH) на 5 августа составляет около $1800, торгуясь ниже нисходящей линии тренда и уровня $1900. Ключевое сопротивление находится в диапазоне $1887-$1918 (где расположены 20-дневная и 100-дневная скользящие средние). Прорыв выше этой зоны может открыть путь к психологически важной отметке в $2000, а затем и к уровням $2300-$2500. Хотя цена выше 50-дневной SMA ($1788), общий импульс остается слабым, и четкий восходящий тренд не сформирован. Параллельно в сообществе Ethereum ведутся дискуссии вокруг предложения EIP-8361, которое предполагает сжигание вознаграждений валидаторов при достижении доли стейкинга более 50% для контроля инфляции. Однако это предложение еще не одобрено. Аналитики отмечают, что способность Ethereum преодолеть $2000 и продолжить рост будет в большей степени зависеть от рыночного спроса и институциональных инвестиций, чем от потенциального внедрения EIP-8361.

cryptonews.ru13 мин. назад

Сможет ли цена Ethereum преодолеть отметку в 2000 долларов? Обсуждения по поводу EIP-8361 продолжаются

cryptonews.ru13 мин. назад

Chainstack добавляет поддержку Robinhood Chain для управляемых и самостоятельно размещенных узлов

Платформа Web3-инфраструктуры Chainstack добавила поддержку блокчейн-сети Robinhood Chain для своих трех моделей развертывания узлов: глобальные узлы, выделенные узлы и Chainstack Self-Hosted. Robinhood Chain — это децентрализованная сеть второго уровня для Ethereum, совместимая с EVM, построенная на Arbitrum Orbit. Она ориентирована на финансовые операции и токенизированные реальные активы (RWA), предлагая высокую скорость (блок каждые 100 мс) и используя ETH для газа. Chainstack предлагает три варианта: * **Глобальные узлы:** Масштабируемые балансируемые RPC-конечные точки. * **Выделенные узлы:** Изолированные экземпляры с неограниченными запросами. * **Chainstack Self-Hosted:** Управление узлами в собственной инфраструктуре клиента (облако, on-premise). Это ключевое решение для регулируемых организаций (эмитентов, брокеров), которым требуется полный контроль над размещением данных. Технический директор Chainstack Евгений Асеев подчеркивает, что вариант самостоятельного размещения позволяет командам, особенно в регулируемой сфере RWA, преодолеть инфраструктурные ограничения, не перестраивая свой стек. Конечные точки Chainstack для основной (chain ID 4663) и тестовой (chain ID 46630) сетей Robinhood Chain уже доступны. Платформа поддерживает более 70 блокчейнов, включая Ethereum, Solana и Polygon.

cryptonews.ru16 мин. назад

Chainstack добавляет поддержку Robinhood Chain для управляемых и самостоятельно размещенных узлов

cryptonews.ru16 мин. назад

Торговля

Спот
活动图片