Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

bitcoinist发布于2026-03-18更新于2026-03-18

文章摘要

Bitrefill, a Swedish crypto e-commerce platform, disclosed a cyberattack on March 1, 2026, attributed to North Korean hackers linked to the Lazarus group. The breach began with a compromised employee laptop, allowing attackers to access sensitive data, including production secrets. Suspicious purchasing patterns led to the discovery that hot wallets were drained, with funds redirected to attacker-controlled addresses. Approximately 18,500 purchase records were exposed, containing limited user data such as email addresses, crypto payment addresses, and IPs. For about 1,000 purchases, encrypted names may have been accessed. Bitrefill is enhancing cybersecurity through external reviews, tighter access controls, and improved monitoring. The company stated it remains well-funded and will cover losses from operational capital.

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group.

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups.

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers.

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach.

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses.

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys.

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations.

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences.

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital... We will continue to do our best to continue deserving your trust.

The daily chart shows the total crypto market cap at $2.52 trillion. Source: TOTAL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

相关问答

QWhat was the victim of the suspected North Korean cyberattack and when did it occur?

AThe victim was the Sweden-based crypto e-commerce platform Bitrefill, and the attack occurred on March 1, 2026.

QWhich notorious hacking groups are suspected to be behind the attack on Bitrefill?

AThe attack is suspected to have been carried out by North Korean hackers linked to the Lazarus and Bluenoroff groups.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe attackers initially gained access through a compromised employee laptop, from which they extracted legacy credentials.

QWhat type of customer data was exposed in the breach, and how many records were affected?

AApproximately 18,500 purchase records were exposed, containing limited customer information such as email addresses, cryptocurrency payment addresses, IP addresses, and for about 1,000 purchases, encrypted names.

QWhat steps is Bitrefill taking to strengthen its cybersecurity after the attack?

ABitrefill is enhancing its cybersecurity by conducting external reviews and penetration tests, tightening internal access, improving logging and monitoring, refining incident response protocols, and collaborating with security experts and law enforcement.

你可能也喜欢

单日暴跌 30%,海耶斯突然清仓,ZEC 为何被爆安全问题?

6月5日,Zcash创始人Zooko Wilcox等人披露其隐私层Orchard池存在关键健全性漏洞,攻击者可利用该漏洞在隐蔽环境下无限伪造ZEC。尽管项目方此前已紧急完成网络升级修复,但详细披露后ZEC价格剧烈波动,单日跌幅一度超30%,最低触及411美元附近。 此次漏洞源于Orchard电路中的椭圆曲线乘法约束不足,允许攻击者构造看似有效的交易,在隐私池内凭空生成ZEC。由于Orchard的隐私特性,链上无法区分真伪,导致池内用户资产可能被变相稀释。Zcash创始人坦言,密码学上无法证明修复前漏洞是否已被利用,此声明加剧了市场恐慌。 漏洞由安全研究员Taylor Hornby借助Anthropic最新AI模型Opus 4.8在针对性审查中发现,凸显了AI工具在安全审计中的强大能力,也意味着攻击者可能利用类似工具加速漏洞挖掘。Orchard自2022年激活以来历经多次审计仍存在缺陷,这对依赖复杂密码学实现的隐私项目敲响了警钟。 事件发生后,知名投资者Arthur Hayes宣布已清仓其全部ZEC持仓。此次事件直接挑战了隐私币“技术可信即核心价值”的叙事,促使行业重新审视隐私技术从理论到实践过程中的安全鸿沟。在AI驱动的攻防新常态下,依赖“未被发现即安全”的侥幸心理已不可行,持续主动的安全审查与快速响应机制变得至关重要。

foresightnews_api9分钟前

单日暴跌 30%,海耶斯突然清仓,ZEC 为何被爆安全问题?

foresightnews_api9分钟前

破除 DeFi 循环清算魔咒,Vitalik 提出了新方案

Vitalik Buterin 提出了一种新的 DeFi 设计思路,旨在解决传统抵押借贷协议中自动清算机制加剧市场波动的根本问题。其核心提议是:以期权为底层构建合成资产,从产品设计上彻底移除强制清算环节。 传统模式(如 Aave)中,一旦抵押品价格跌破预设阈值,仓位会被系统自动强制平仓。这在市场暴跌时容易引发集中抛售,放大下跌幅度,形成“清算-抛压-再清算”的恶性循环。 Vitalik 的新方案将 1 枚 ETH 拆分为两类关联的期权资产(P 和 N)。其价值总和始终等于 1 ETH,但各自相对于目标价格(如美元)的敞口会随着市场行情逐渐偏移,而不会发生瞬间的清算事件。风险从“断崖式平仓”转变为“渐进式价值偏离”,用户需要通过主动调仓(如轮换至不同行权价的期权)来管理风险,将再平衡的主动权交还给用户。 该设计还能降低对高频率、实时预言机报价的依赖,允许采用容错率更高、延迟结算的定价机制,减少因预言机异常或市场操纵引发的风险。 然而,该方案也存在待解挑战:用户需容忍资产价值的持续偏移与定期调仓的成本;依赖 AMM 进行频繁调仓可能产生高滑点;需要发展新的做市商模式提供流动性。它更适合作为对冲或指数追踪工具,而非要求严格锚定(如1美元)的会计结算型稳定币。 目前,该提案尚处于理论探讨阶段,但标志着行业顶尖思维开始质疑并寻求替代“强制清算”这一 DeFi 固有风控模式的可能性,为未来设计提供了新方向。

foresightnews_api12分钟前

破除 DeFi 循环清算魔咒,Vitalik 提出了新方案

foresightnews_api12分钟前

交易

现货
合约

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

2.4k人学过发布于 2025.01.15更新于 2026.06.02

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片