Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

bitcoinist发布于2026-03-18更新于2026-03-18

文章摘要

Bitrefill, a Swedish crypto e-commerce platform, disclosed a cyberattack on March 1, 2026, attributed to North Korean hackers linked to the Lazarus group. The breach began with a compromised employee laptop, allowing attackers to access sensitive data, including production secrets. Suspicious purchasing patterns led to the discovery that hot wallets were drained, with funds redirected to attacker-controlled addresses. Approximately 18,500 purchase records were exposed, containing limited user data such as email addresses, crypto payment addresses, and IPs. For about 1,000 purchases, encrypted names may have been accessed. Bitrefill is enhancing cybersecurity through external reviews, tighter access controls, and improved monitoring. The company stated it remains well-funded and will cover losses from operational capital.

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group.

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups.

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers.

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach.

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses.

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys.

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations.

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences.

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital... We will continue to do our best to continue deserving your trust.

The daily chart shows the total crypto market cap at $2.52 trillion. Source: TOTAL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

热门币种推荐

相关问答

QWhat was the victim of the suspected North Korean cyberattack and when did it occur?

AThe victim was the Sweden-based crypto e-commerce platform Bitrefill, and the attack occurred on March 1, 2026.

QWhich notorious hacking groups are suspected to be behind the attack on Bitrefill?

AThe attack is suspected to have been carried out by North Korean hackers linked to the Lazarus and Bluenoroff groups.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe attackers initially gained access through a compromised employee laptop, from which they extracted legacy credentials.

QWhat type of customer data was exposed in the breach, and how many records were affected?

AApproximately 18,500 purchase records were exposed, containing limited customer information such as email addresses, cryptocurrency payment addresses, IP addresses, and for about 1,000 purchases, encrypted names.

QWhat steps is Bitrefill taking to strengthen its cybersecurity after the attack?

ABitrefill is enhancing its cybersecurity by conducting external reviews and penetration tests, tightening internal access, improving logging and monitoring, refining incident response protocols, and collaborating with security experts and law enforcement.

你可能也喜欢

XRP持有者转为盈利,但现货需求已消失:1.10美元支撑能否守住?

XRP近期市场结构发出矛盾信号:现货交易活动减弱,资金转向衍生品市场。尽管交易量持续下降,价格仍维持在1.086至1.113美元区间盘整,表明多空双方均未取得决定性优势。 通常情况下,现货活动减弱会降低投机兴趣。然而,XRP的未平仓合约却增加了约5.9%,达到4.238亿,同时预估杠杆率升至0.162。这种分化很关键,因为衍生品可以维持头寸而无需向市场注入新资金。随着现货流入和流出暴跌约99%,杠杆交易者日益成为XRP价格发现的主导力量。这也解释了价格为何持续盘整而非选择方向突破。但除非现货需求回归以验证这些头寸,否则不断增长的杠杆使XRP在市场情绪突变时极易遭遇急剧平仓。 市场可持续性的一个关键因素是持有者盈利状况。随着XRP的30日MVRV比率回升至1.03,近期买家已重返盈利状态。这一改善与比特币、以太坊等其他主流资产同步,表明投资者情绪正在广泛复苏,而非仅限于XRP。 盈利状态的改变也影响了市场激励机制。随着更多短期持有者脱离未实现亏损,持币压力通常会让位于获利了结的意愿。尽管XRP价格仍低于历史抛售区,但由于缺乏新的需求入场,且获利了结压力可能显现,当前价格走势的可持续性正面临越来越大的挑战。综上所述,虽然持有者恢复盈利,但涨势更多由衍生品市场的杠杆驱动,而非真实的现货需求。随着获利了结压力增大以及对可持续性的怀疑升温,1.10美元的支撑位正面临风险。

ambcrypto44分钟前

XRP持有者转为盈利,但现货需求已消失:1.10美元支撑能否守住?

ambcrypto44分钟前

交易

现货

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

3.0k人学过发布于 2025.01.15更新于 2026.06.02

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片