Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

bitcoinist发布于2026-03-18更新于2026-03-18

文章摘要

Bitrefill, a Swedish crypto e-commerce platform, disclosed a cyberattack on March 1, 2026, attributed to North Korean hackers linked to the Lazarus group. The breach began with a compromised employee laptop, allowing attackers to access sensitive data, including production secrets. Suspicious purchasing patterns led to the discovery that hot wallets were drained, with funds redirected to attacker-controlled addresses. Approximately 18,500 purchase records were exposed, containing limited user data such as email addresses, crypto payment addresses, and IPs. For about 1,000 purchases, encrypted names may have been accessed. Bitrefill is enhancing cybersecurity through external reviews, tighter access controls, and improved monitoring. The company stated it remains well-funded and will cover losses from operational capital.

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group.

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups.

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers.

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach.

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses.

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys.

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations.

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences.

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital... We will continue to do our best to continue deserving your trust.

The daily chart shows the total crypto market cap at $2.52 trillion. Source: TOTAL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

相关问答

QWhat was the victim of the suspected North Korean cyberattack and when did it occur?

AThe victim was the Sweden-based crypto e-commerce platform Bitrefill, and the attack occurred on March 1, 2026.

QWhich notorious hacking groups are suspected to be behind the attack on Bitrefill?

AThe attack is suspected to have been carried out by North Korean hackers linked to the Lazarus and Bluenoroff groups.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe attackers initially gained access through a compromised employee laptop, from which they extracted legacy credentials.

QWhat type of customer data was exposed in the breach, and how many records were affected?

AApproximately 18,500 purchase records were exposed, containing limited customer information such as email addresses, cryptocurrency payment addresses, IP addresses, and for about 1,000 purchases, encrypted names.

QWhat steps is Bitrefill taking to strengthen its cybersecurity after the attack?

ABitrefill is enhancing its cybersecurity by conducting external reviews and penetration tests, tightening internal access, improving logging and monitoring, refining incident response protocols, and collaborating with security experts and law enforcement.

你可能也喜欢

交易

现货
合约

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

2.1k人学过发布于 2025.01.15更新于 2025.03.21

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片