Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

bitcoinistОпубликовано 2026-03-18Обновлено 2026-03-18

Введение

Bitrefill, a Swedish crypto e-commerce platform, disclosed a cyberattack on March 1, 2026, attributed to North Korean hackers linked to the Lazarus group. The breach began with a compromised employee laptop, allowing attackers to access sensitive data, including production secrets. Suspicious purchasing patterns led to the discovery that hot wallets were drained, with funds redirected to attacker-controlled addresses. Approximately 18,500 purchase records were exposed, containing limited user data such as email addresses, crypto payment addresses, and IPs. For about 1,000 purchases, encrypted names may have been accessed. Bitrefill is enhancing cybersecurity through external reviews, tighter access controls, and improved monitoring. The company stated it remains well-funded and will cover losses from operational capital.

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group.

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups.

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers.

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach.

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses.

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys.

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations.

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences.

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital... We will continue to do our best to continue deserving your trust.

The daily chart shows the total crypto market cap at $2.52 trillion. Source: TOTAL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

Связанные с этим вопросы

QWhat was the victim of the suspected North Korean cyberattack and when did it occur?

AThe victim was the Sweden-based crypto e-commerce platform Bitrefill, and the attack occurred on March 1, 2026.

QWhich notorious hacking groups are suspected to be behind the attack on Bitrefill?

AThe attack is suspected to have been carried out by North Korean hackers linked to the Lazarus and Bluenoroff groups.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe attackers initially gained access through a compromised employee laptop, from which they extracted legacy credentials.

QWhat type of customer data was exposed in the breach, and how many records were affected?

AApproximately 18,500 purchase records were exposed, containing limited customer information such as email addresses, cryptocurrency payment addresses, IP addresses, and for about 1,000 purchases, encrypted names.

QWhat steps is Bitrefill taking to strengthen its cybersecurity after the attack?

ABitrefill is enhancing its cybersecurity by conducting external reviews and penetration tests, tightening internal access, improving logging and monitoring, refining incident response protocols, and collaborating with security experts and law enforcement.

Похожее

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.2k просмотров всегоОпубликовано 2025.01.15Обновлено 2025.03.21

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.2k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片