Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

bitcoinist发布于2026-03-18更新于2026-03-18

文章摘要

Bitrefill, a Swedish crypto e-commerce platform, disclosed a cyberattack on March 1, 2026, attributed to North Korean hackers linked to the Lazarus group. The breach began with a compromised employee laptop, allowing attackers to access sensitive data, including production secrets. Suspicious purchasing patterns led to the discovery that hot wallets were drained, with funds redirected to attacker-controlled addresses. Approximately 18,500 purchase records were exposed, containing limited user data such as email addresses, crypto payment addresses, and IPs. For about 1,000 purchases, encrypted names may have been accessed. Bitrefill is enhancing cybersecurity through external reviews, tighter access controls, and improved monitoring. The company stated it remains well-funded and will cover losses from operational capital.

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group.

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups.

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers.

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach.

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses.

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys.

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations.

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences.

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital... We will continue to do our best to continue deserving your trust.

The daily chart shows the total crypto market cap at $2.52 trillion. Source: TOTAL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

热门币种推荐

相关问答

QWhat was the victim of the suspected North Korean cyberattack and when did it occur?

AThe victim was the Sweden-based crypto e-commerce platform Bitrefill, and the attack occurred on March 1, 2026.

QWhich notorious hacking groups are suspected to be behind the attack on Bitrefill?

AThe attack is suspected to have been carried out by North Korean hackers linked to the Lazarus and Bluenoroff groups.

QHow did the attackers initially gain access to Bitrefill's systems?

AThe attackers initially gained access through a compromised employee laptop, from which they extracted legacy credentials.

QWhat type of customer data was exposed in the breach, and how many records were affected?

AApproximately 18,500 purchase records were exposed, containing limited customer information such as email addresses, cryptocurrency payment addresses, IP addresses, and for about 1,000 purchases, encrypted names.

QWhat steps is Bitrefill taking to strengthen its cybersecurity after the attack?

ABitrefill is enhancing its cybersecurity by conducting external reviews and penetration tests, tightening internal access, improving logging and monitoring, refining incident response protocols, and collaborating with security experts and law enforcement.

你可能也喜欢

意大利央行未发现稳定币在汇款中存在系统性优势

意大利银行的一项研究显示,稳定币在跨境汇款中并未展现出持续的成本与速度优势。其潜在优势被法币出入金手续费以及本地支付基础设施的处理流程所抵消。 研究比较了通过200 USDC在意大利与巴西、阿根廷、日本、阿联酋和南非等10条双向通道进行汇款的成本与结算时间,并与标准汇款服务进行对比。 结果显示,稳定币转账的总成本在0.3%到近9%之间波动,具体取决于汇款方向。在具备即时支付系统的通道中,结算可在20分钟内完成;若缺乏此类基础设施,则需一至两个工作日。 主要成本和延迟源于货币兑换以及当地基础设施的质量。区块链网络手续费并非主要因素。 尽管在大多数研究通道中,稳定币成本低于世界银行统计的全球平均汇款成本(6.65%),但与传统汇款服务商Wise相比,仅在七条可比通道中的三条具备成本优势。 研究者认为,若稳定币能直接用于商品服务消费而无需兑换成当地货币,其优势将更为明显。同时指出,禁令性监管无法消除市场对稳定币的需求,而过严的规则只会增加零售用户的使用难度。 此外,报告提及,稳定币总市值在7月已从5月峰值下跌超100亿美元,至约3100亿美元,创下自2022年5月Terra崩溃以来的最大月度跌幅。

cryptonews.ru1小时前

意大利央行未发现稳定币在汇款中存在系统性优势

cryptonews.ru1小时前

比特币热潮正酣:塞勒尔新声明引发关于购买的猜测

纳斯达克上市公司MicroStrategy(代码:MSTR)的执行董事长迈克尔·塞勒于8月2日发布信息“Bitcoin Drive engaged”(比特币驱动已启动),再次引发市场对于该公司将在周一宣布新一轮比特币购买的猜测。其周日的帖子附带了该公司惯用的购买追踪图表,这符合塞勒通常在每周财报发布前暗示其金库变动的做法。 塞勒的附图报告显示,MicroStrategy的比特币储备为843,775枚BTC,市值约532.5亿美元。平均购买成本为每枚75,653美元,未实现亏损为105.8亿美元(-16.58%)。截至8月2日,累计进行了113次购买操作。 此前在7月27日,类似的周日信号曾预告了公司的公告,当时塞勒发文称“我们还需要一种颜色”,随后MicroStrategy披露了其更大的现金储备。这种时间上的巧合强化了市场对周一将发布新金库状况公告的预期。 然而,该公司实时账本显示,在最近两次共计出售3,588枚BTC(包括1,363枚和2,225枚)后,其比特币储备已从847,363枚降至843,775枚。根据提交给美国证券交易委员会(SEC)的文件,这些出售是为了资助优先股支付并补充美元储备。最近的报告还显示,在截至7月26日的一周内,MicroStrategy没有购买任何比特币,同时将其美元储备增加至约37.5亿美元,这使其优先股股息和债务利息的预计覆盖期限延长至约2.1年。 财务风险依然高企,该公司报告2026年第二季度运营亏损83.3亿美元,与上年同期140.3亿美元的运营利润形成急剧逆转。这些业绩包含了公司数字资产方面83.2亿美元的未实现亏损,而2025年第二季度为未实现利润140.5亿美元。 管理层还可能通过额外出售比特币获得高达12.5亿美元,以补充用于支付优先股股息和债务利息的美元储备。因此,预计周一的披露将揭示“Bitcoin Drive”信息是否标志着资产积累的恢复,因为MicroStrategy需要在平衡其843,775枚BTC自有储备与不断增长的现金负债和积极的资本管理之间做出抉择。

cryptonews.ru1小时前

比特币热潮正酣:塞勒尔新声明引发关于购买的猜测

cryptonews.ru1小时前

交易

现货

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

3.3k人学过发布于 2025.01.15更新于 2026.06.02

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片