Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcryptoXuất bản vào 2026-03-17Cập nhật gần nhất vào 2026-03-17

Tóm tắt

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Câu hỏi Liên quan

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

Nội dung Liên quan

Coldcard kêu gọi người dùng chuyển Bitcoin vì lỗ hổng vẫn đang bị khai thác

Công ty Coldcard Wallet đã đưa ra cảnh báo khẩn cấp, kêu gọi người dùng chuyển ngay Bitcoin của họ sau khi xác nhận một lỗ hổng bảo mật nghiêm trọng vẫn đang bị khai thác. Lỗ hổng này, tồn tại từ năm 2021, đã dẫn đến tổn thất ước tính lên tới 114 triệu USD sau đợt tấn công mới nhất. Công ty nhấn mạnh: "Hãy coi đây là việc khẩn cấp. Hãy chuyển số tiền của bạn." Nguy cơ đặc biệt cao với những người dùng ít trực tuyến, vì bản sửa lỗi phải được thực hiện thủ công. Hướng dẫn cụ thể là cập nhật phần mềm, tạo cụm từ khóa (seed phrase) mới và chuyển tiền sang ví mới. Lỗ hổng ảnh hưởng đến một số thiết bị và phiên bản phần mềm nhất định. Chủ sở hữu ví Coldcard Mk3 (năm 2019) cần hành động ngay nếu thiết bị chạy phần mềm từ phiên bản 4.0.1. Người dùng Mk4, Mk5 và Q với phần mềm cũ hơn 5.6.0 hoặc 1.5.0Q cũng cần cập nhật và tạo ví mới. Ngoại lệ duy nhất là những người đã sử dụng chức năng "ném xúc xắc" để tạo khóa, vì phương pháp này không liên quan đến mã bị lỗi. Các chuyên gia giải thích rằng seed phrase là chìa khóa chính; nếu nó được tạo ra với độ ngẫu nhiên thấp, kẻ tấn công có thể đoán được và đánh cắp tiền. Vince Buzon từ Ledger chỉ ra rằng sự cố này bắt nguồn từ lỗi trong một phương pháp tạo số ngẫu nhiên cụ thể, và nhấn mạnh tầm quan trọng của phần cứng bảo mật. Giá Bitcoin vào thời điểm đó vẫn ổn định quanh mức 63.800 USD bất chấp thông báo.

cryptonews.ru8 phút trước

Coldcard kêu gọi người dùng chuyển Bitcoin vì lỗ hổng vẫn đang bị khai thác

cryptonews.ru8 phút trước

Dự báo giá Ethereum: Tại sao ETH vẫn ổn định sau năm tuần liên tiếp có dòng tiền vào ETF?

Dự báo giá Ethereum: Tại sao ETH vẫn ổn định sau năm tuần liên tiếp dòng tiền vào ETF? Bài viết phân tích tình hình giá Ethereum (ETH) đang giao dịch quanh mức 1.867,68 USD, hầu như không biến động bất chấp hai yếu tố tích cực: dòng tiền vào ETF spot ETH liên tục trong năm tuần và một đề xuất giảm phát (EIP-8363) có thể thắt chặt nguồn cung. Về mặt kỹ thuật, ETH đang giữ vững ngưỡng hỗ trợ Fibonacci 0.382 ở 1.837,76 USD nhưng vẫn bị kháng cự bởi đường xu hướng giảm quanh vùng 1.900-1.940 USD. Chỉ báo MACD cho thấy đà tăng chưa được xác nhận, xu hướng chính vẫn là đi ngang. Một điểm nhấn là dòng tiền vào ETF spot ETH vẫn duy trì, với mức ròng 42,33 triệu USD chỉ trong hai ngày đầu tuần (tính đến 5/8/2026), hướng tới tuần tăng thứ năm liên tiếp. Đề xuất EIP-8363 (Tapered Issuance Burn), được ủng hộ bởi một số nhà nghiên cứu, nhằm đốt phần thưởng staking khi lượng ETH stake đạt ngưỡng nhất định, có thể tạo ra cú sốc giảm nguồn cung. Tuy nhiên, đề xuất này cũng gây tranh cãi vì lo ngại làm giảm lợi nhuận staking, gây bất lợi cho các validator nhỏ lẻ và giảm sự hấp dẫn đối với tổ chức. Dự báo giá: * Kịch bản tăng (Mục tiêu: 2.042 USD): Nếu ETH phá vỡ đường xu hướng giảm và vùng kháng cự 1.940 USD, kết hợp với dòng tiền ETF và kỳ vọng vào EIP-8363, giá có thể hướng đến mức Fibonacci 0.618. * Kịch bản giảm (Mức rủi ro: 1.711 USD): Nếu đường xu hướng giảm tiếp tục đẩy lùi giá, ETH mất ngưỡng hỗ trợ 1.837,76 USD và tranh cãi quanh EIP-8363 ảnh hưởng đến tâm lý, giá có thể kiểm tra lại vùng hỗ trợ thấp hơn.

cryptonews.ru11 phút trước

Dự báo giá Ethereum: Tại sao ETH vẫn ổn định sau năm tuần liên tiếp có dòng tiền vào ETF?

cryptonews.ru11 phút trước

Giá Ethereum có thể vượt qua mốc 2000 đô la không? Thảo luận về EIP-8361 vẫn tiếp diễn

Tính đến ngày 5 tháng 8, Ethereum (ETH) đang giao dịch quanh mức 1.800 USD. Giá đang bị mắc kẹt dưới một đường xu hướng giảm và phải đối mặt với vùng kháng cự từ 1.887 đến 1.918 USD. Việc phá vỡ trên vùng này có thể mở đường cho giá chạm mốc tâm lý 2.000 USD. Về phân tích kỹ thuật, trên biểu đồ ngày, giá ETH hiện giao dịch dưới đường trung bình động đơn giản (SMA) 20 ngày và 100 ngày, nhưng vẫn nằm trên SMA 50 ngày. Trên khung thời gian 4 giờ, giá đang tiếp cận vùng phá vỡ quan trọng 1.875-1.885 USD. Tuy nhiên, động lực tăng hiện vẫn còn yếu. Song song với diễn biến giá, đề xuất nâng cấp EIP-8361 đang được thảo luận trong cộng đồng Ethereum. Đề xuất này nhằm giảm phần thưởng phát hành mới khi tỷ lệ ETH được staking tăng lên, bằng cách đốt phần thưởng của validator. Tuy nhiên, đề xuất vẫn chưa được thông qua và còn nhiều ý kiến trái chiều. Các chuyên gia như Michael van de Poppe nhận định mức 1.800 USD là hỗ trợ then chốt. Nếu vượt qua được 2.000 USD, ETH có thể nhắm đến các mục tiêu 2.300 và 2.500 USD. Tuy nhiên, khả năng phục hồi bền vững của Ethereum phụ thuộc nhiều hơn vào nhu cầu thị trường và dòng vốn tổ chức so với tác động của EIP-8361.

cryptonews.ru12 phút trước

Giá Ethereum có thể vượt qua mốc 2000 đô la không? Thảo luận về EIP-8361 vẫn tiếp diễn

cryptonews.ru12 phút trước

Chainstack bổ sung hỗ trợ cho Robinhood Chain cho các nút được quản lý và tự lưu trữ

Chainstack, nền tảng cơ sở hạ tầng Web3, đã bổ sung hỗ trợ cho Robinhood Chain trên cả ba mô hình triển khai: nút toàn cầu, nút chuyên dụng và Chainstack Self-Hosted. Robinhood Chain là mạng Lớp 2 Ethereum tương thích EVM, được xây dựng trên Arbitrum Orbit, tập trung vào giao dịch tài chính và tài sản thực được token hóa (RWA), với thời gian tạo khối 100ms và sử dụng ETH làm phí gas. Chainstack cung cấp ba lựa chọn: **Nút toàn cầu** có khả năng mở rộng linh hoạt, phù hợp cho ví và dApp; **Nút chuyên dụng** là máy chủ riêng hiệu suất cao không giới hạn yêu cầu, lý tưởng cho sàn giao dịch và giao thức RWA; **Chainstack Self-Hosted** cho phép khách hàng chạy nút trong môi trường riêng (đám mây, tại chỗ) với bảng điều khiển quản lý đầy đủ, đáp ứng yêu cầu tuân thủ và chủ quyền dữ liệu nghiêm ngặt cho các tổ chức phát hành được quản lý. Tính năng tự lưu trữ này rất quan trọng, cho phép các tổ chức tuân thủ tích hợp cơ sở hạ tầng blockchain vào hệ thống riêng mà không cần thay đổi ngăn xếp công nghệ. Robinhood Chain gia nhập hơn 70 mạng được Chainstack hỗ trợ. Các nhà phát triển có thể tạo tài khoản để truy cập endpoint cho mạng chính (chain ID 4663) và mạng thử nghiệm (chain ID 46630).

cryptonews.ru15 phút trước

Chainstack bổ sung hỗ trợ cho Robinhood Chain cho các nút được quản lý và tự lưu trữ

cryptonews.ru15 phút trước

Giao dịch

Giao ngay
活动图片