Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcrypto发布于2026-03-17更新于2026-03-17

文章摘要

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

相关问答

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

你可能也喜欢

Chainstack为托管和自托管节点添加对Robinhood Chain的支持

2026年8月5日,Web3基础设施平台Chainstack宣布在其全球节点、专用节点及Chainstack自托管三种部署模式中,新增对Robinhood Chain的支持。该网络主网已于2026年7月1日上线。 Robinhood Chain是一个基于Arbitrum Orbit Nitro堆栈构建的、专注于金融交易和现实世界资产代币化的以太坊二层网络。它兼容EVM,区块生成时间为100毫秒,使用ETH作为燃料费,并通过Blob数据提交至以太坊一层实现约13分钟后的最终确定性。其交易排序采用“先到先得”原则,排序结果取决于端点延迟而非燃料费,这使得节点部署成为影响交易执行的关键因素。 Chainstack提供的三种部署路径各有侧重:全球节点为弹性负载均衡的RPC端点,适合钱包、DApp及生产扩展;专用节点提供无请求限制的高性能独立实例,适合交易平台、索引器和高吞吐量RWA协议;Chainstack自托管方案允许客户在自有云、本地环境或专属硬件上,通过统一的Kubernetes控制面板管理节点,满足受监管发行商或对数据主权有严格要求的机构的需求。 Chainstack联合创始人兼CTO尤金·阿瑟夫指出,对于受监管实体而言,节点数据的存放位置可能直接决定产品能否发布。Chainstack通过在同一管理平面上提供托管与自托管部署,使团队无需重构技术栈即可将基础设施集成到自有环境中。 目前,用户已可通过Chainstack账户在Robinhood Chain主网(链ID 4663)和测试网(链ID 46630)上部署节点并使用HTTPS或WSS端点。Chainstack为评估团队提供免费访问权限及测试网代币水龙头。

cryptonews.ru16分钟前

Chainstack为托管和自托管节点添加对Robinhood Chain的支持

cryptonews.ru16分钟前

交易

现货
活动图片