Bitrefill Cyberattack Exposes 18,500 Records, Lazarus Group Suspected

TheNewsCrypto2026-03-18 tarihinde yayınlandı2026-03-18 tarihinde güncellendi

Özet

Bitrefill, a cryptocurrency payment platform, was targeted by a cyberattack attributed to the North Korea-linked Lazarus Group on March 1, 2026. The breach, which began with a compromised employee laptop, exposed approximately 18,500 customer purchase records, including email addresses, crypto payment addresses, and IP data. The attackers primarily focused on moving funds from hot wallets and exploiting the gift card system, rather than stealing full customer data. Bitrefill quickly detected the unusual activity, shut down systems to prevent further damage, and has committed to covering all losses with its own funds. The company has since enhanced security measures, including stronger access controls and improved monitoring, and confirmed that most services are back to normal. This was Bitrefill's first major security breach in over a decade.

Bitrefill, a cryptocurrency payment platform, reported that it was the target of a cyberattack on March 1, 2026, and it attributed the attack to the Lazarus Group, a hacker collective associated with North Korea. The attack exposed about 18,500 customer purchase records and impacted several aspects of Bitrefill’s systems, including its cryptocurrency wallets.

How this Breach Happened

According to the firm, the breach began with the compromised employee’s laptop. In this case, the hackers were able to enter Bitrefill’s infrastructure and access production keys by moving funds from the hot wallet to exploit its gift card system. The company noticed unusual activity and quickly shut down systems to stop further damage.

The attacker accessed about 18,500 purchase records, which include email addresses, crypto payment addresses, and IP address data. The firm says that the hackers did not try to steal full customer data, and their main focus was on the crypto funds and the gift cards.

Bitrefill confirmed that it will cover all losses using its own funds. The company said it remains financially stable and that most services, including payments and accounts, are now back to normal.

Bitrefill has taken steps to improve security by providing stronger access control, better monitoring systems, external security testing, and faster response systems for future attacks. Additionally, it collaborates with blockchain analysts and security experts. According to Bitrefill, the hack was the company’s first significant security breach in more than ten years. Despite the attack’s damage, the business swiftly responded and resumed operations.

Highlighted Crypto News:

SEC and CFTC Introduce Crypto Classification Framework

TagsBitrefillCryptocurrency

İlgili Sorular

QWhat company was targeted in the cyberattack and who is suspected to be behind it?

ABitrefill, a cryptocurrency payment platform, was targeted, and the attack is attributed to the Lazarus Group, a hacker collective associated with North Korea.

QHow many customer records were exposed in the Bitrefill breach?

AApproximately 18,500 customer purchase records were exposed.

QWhat type of information was accessed in the compromised purchase records?

AThe accessed information includes email addresses, crypto payment addresses, and IP address data.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe breach began with a compromised employee's laptop, which allowed the hackers to enter the infrastructure and access production keys.

QWhat steps has Bitrefill taken to improve its security following the attack?

ABitrefill has implemented stronger access control, better monitoring systems, external security testing, and faster response systems. It is also collaborating with blockchain analysts and security experts.

İlgili Okumalar

Expect news tomorrow: this time the Bank of Japan will announce its interest rate decision! What impact will this have on Bitcoin?

A day before the Bank of Japan's (BOJ) interest rate decision announcement, the Japanese yen surged nearly 3% against the US dollar. The sharp move in the currency market fueled speculation that the Japanese government may have intervened again to support the yen. The USD/JPY pair fell over 400 pips to 158.5, its steepest daily drop since Japan's currency intervention earlier this year. Market participants suspect the rapid, strong yen appreciation could be due to direct foreign currency sales by Japanese authorities, though the Ministry of Finance has made no official statement. The yen had previously fallen to its weakest level against the dollar in nearly 40 years. In late April and May, the government intervened with roughly 9.6 trillion yen to prevent the USD/JPY from rising sustainably above 160, but the yen faced renewed selling pressure afterward. Investors are now focused on the BOJ's rate decision and its signals on future monetary policy. Potential hawkish signals from the BOJ are seen as a factor that could support further yen strength. A sharp yen appreciation could create short-term selling pressure on Bitcoin by increasing the risk of unwinding carry trades, where investors borrow low-yielding yen to invest in Bitcoin and other risky assets. This pressure could intensify if the BOJ takes a hawkish stance or raises interest rates.

cryptonews.ru19 dk önce

Expect news tomorrow: this time the Bank of Japan will announce its interest rate decision! What impact will this have on Bitcoin?

cryptonews.ru19 dk önce

Bernstein Reveals Details of Core Scientific's $14 Billion Deal with AMD

Analysts from Bernstein revealed details of a deal between Core Scientific and AMD with a potential total value of over $14 billion. According to the report, initial contracts for 530 MW of capacity could generate this revenue over 15 years, with AMD acting as a credit guarantor for part of the bitcoin miner's infrastructure. The partnership, announced on July 28, has the potential to allocate up to 2.5 GW of data center capacity for AI. Bernstein broke down the 530 MW into 377 MW of direct triple-net lease for AMD and 152 MW for an unnamed cloud provider backed by AMD's credit. This structure is seen as lowering financing costs and counterparty risk. AMD also received warrants to buy 30 million Core Scientific shares at $23.47 each, which vest upon reaching the 2.5 GW target. Average annual revenue from the deal is estimated at around $0.9 billion, or about $1.8 million per megawatt, which is 5-25% below recent AI hosting deals by other miners. However, the 377 MW triple-net lease for AMD carries a margin close to 100%. Core Scientific expects capital expenditures for the deal to be $11-12 million per MW, totaling about $6 billion. Bernstein views this partnership as a new phase in the transformation of former bitcoin miners into AI infrastructure operators, with AI chipmakers like AMD now acting as direct anchor tenants. Recent similar deals include Hut 8 allocating 704 MW to a tenant believed to be Nvidia, and AMD reserving 200 MW with Riot Platforms. Core Scientific also paid Block $41.9 million to terminate a mining chip supply contract as part of its accelerated diversification into AI.

cryptonews.ru1 saat önce

Bernstein Reveals Details of Core Scientific's $14 Billion Deal with AMD

cryptonews.ru1 saat önce

İşlemler

Spot
活动图片