Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoОпубліковано о 2026-03-17Востаннє оновлено о 2026-03-17

Анотація

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Пов'язані питання

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Пов'язані матеріали

Robinhood's Bigger Basket

"Robinhood's Bigger Basket" A few weeks ago, the author described Robinhood as a financial supermarket, bundling services from stocks to crypto. After watching the Q2 2026 earnings call, this view was seen as an understatement. The real power is not just attracting new customers, but making existing users engage more deeply. Key performance highlights: * Revenue surpassed $5B annualized, faster than legacy brokers like Charles Schwab. * Paying users grew 7% YoY to 28.4M, but Average Revenue Per User (ARPU) surged 24% to $187. * User activity intensified: per-user stock notional volume rose 56% and options contracts rose 43%, while the number of users trading these assets grew much slower (13% and 3% respectively). The Robinhood Gold subscription is a critical engine. Nearly half of new users sign up for Gold, which then acts as a gateway. Gold users hold 4.2x more assets and are 3.1x more likely to use retirement products than regular users. This creates a powerful cross-sell flywheel where using one product (e.g., prediction markets) increases adoption of others (e.g., IRAs). The future catalysts are Robinhood Chain and the upcoming Robinhood Social feed. * **Robinhood Chain** integrates services (tokenized stocks, lending, perpetuals) into a single, composable platform, reducing friction for cross-product usage. * **Robinhood Social** will internalize the trading idea generation process. Verified portfolios within the app could build trust and move the entire "idea-to-execution" loop inside Robinhood. Together, these act as neutral layers that drive engagement and value accumulation across Robinhood's ecosystem, similar to how Costco's store layout drives membership sales. Despite cyclical concerns in areas like crypto trading, Robinhood's diversified portfolio of 13 business lines each with over $100M in Annual Recurring Revenue (ARR) creates stability. Different product cycles offset each other within a single user's account. The company's unique advantage is transforming a single customer relationship into a compounding, self-diversifying revenue node spanning traditional and crypto finance, amplified by its native blockchain.

marsbit2 год тому

Robinhood's Bigger Basket

marsbit2 год тому

Germany's Decades-Long Lead Lost as China's Machine Tools Quietly Rise to Global No.1

For decades, Germany held the top spot in global machine tool exports, but in 2025, China officially surpassed it for the first time, with its export value reaching 21% of the global market share. This article explores how China transformed from a heavily import-dependent nation to an export leader in this foundational industry for modern manufacturing. It begins by explaining the immense technical challenges in building high-end machine tools. Precision machining faces persistent physical obstacles like thermal expansion, vibration, and component wear, demanding top-tier core components like spindles, ball screws, and CNC systems. Historically, China relied on imports for over 90% of these critical components, and domestic machine tools suffered from short lifespans between failures (MTBF), making them unreliable for industrial use. The article credits the state-backed "04 Special Project" (2009-2020) for laying a crucial foundation. It boosted the market share of domestic high-end CNC systems from below 1% to nearly 32% and significantly improved overall machine reliability. However, the primary driver for China's rise was the massive and fast-evolving domestic market, particularly in the new-energy vehicle (NEV) sector. This created unique, high-demand applications like machining large integrated die-castings and complex battery housings. Domestic manufacturers, being close to the world's largest NEV market, rapidly iterated products to meet these new needs, gaining an edge over foreign competitors in certain emerging segments. Despite reaching the top spot in export value, the article stresses this is just a beginning. The current exports are often in specific categories like special-purpose processing machines (e.g., laser, EDM), with key markets in Asia and emerging economies. Furthermore, part of the "Chinese" export volume comes from foreign-owned factories within China. The true test for China's machine tool industry will be building the global trust and service infrastructure required for long-term, reliable operation overseas. The journey from being a buyer restricted by others' export controls to becoming a seller who must manage sensitive equipment exports and build a global support network has just entered a new, more demanding phase.

marsbit2 год тому

Germany's Decades-Long Lead Lost as China's Machine Tools Quietly Rise to Global No.1

marsbit2 год тому

Торгівля

Спот
活动图片