Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

ambcrypto發佈於 2026-03-17更新於 2026-03-17

文章摘要

Bitrefill disclosed a cyberattack on March 1, 2026, in which attackers drained funds from its hot wallets and accessed internal systems. The intrusion began with a compromised employee laptop, leading to the theft of legacy credentials and production secrets. Attackers exploited gift card inventory systems and moved funds to external addresses. Approximately 18,500 purchase records were accessed, including emails, crypto addresses, and metadata, with around 1,000 records including potentially exposed customer names. The investigation revealed similarities with tactics used by the Lazarus Group, though attribution was not definitive. Bitrefill has since restored systems, notified affected users, and strengthened security controls. The company stated it remains financially stable and will cover the losses from operational capital.

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure.

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure.

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

相關問答

QWhat was the initial entry point for the cyberattack on Bitrefill?

AThe intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential.

QWhich threat actor group did the attack show similarities to, according to Bitrefill's investigation?

AThe investigation revealed similarities with the tactics used by the Lazarus Group and its associated unit, Bluenoroff.

QWhat type of customer data was potentially exposed for approximately 1,000 purchases?

AFor around 1,000 purchases, customer names were included. While the data was encrypted, the attackers may have accessed the encryption keys.

QWhat two main company systems did the attackers exploit during the breach?

AThe attackers exploited both its gift card inventory system and crypto infrastructure.

QWhat was the total number of purchase records that were accessed during the security breach?

AApproximately 18,500 purchase records were accessed during the breach.

你可能也喜歡

历史底部信号再现?估值3亿的Messari以1000万贱卖

加密数据平台Messari曾估值3亿美元,近期以约1000万美元被竞争对手Blockworks收购,标志其八年创业历程结束。该公司衰落部分源于AI技术冲击——传统需耗时数周的研究报告如今可借AI工具快速生成,导致其核心业务价值锐减。 Messari的处境并非个例。2025年至2026年间,加密行业众多不发币、依赖产品服务营收的公司陷入困境:数据平台DappRadar、Parsec相继关停,CoinGecko寻求出售;媒体CoinDesk、Bankless大幅裁员或低价被购;链上数据公司Dune也进行了裁员。行业收缩浪潮明显。 风险投资(VC)领域同样遇冷。加密基金数量减半,新基金募资额骤降至峰值期的12%,投资额在半年内暴跌超80%。资本与人才大量流向AI领域,连Multicoin Capital等知名加密基金创始人也转向AI。有投资人形容当前环境为“大灭绝”。 然而,极端悲观信号集聚或暗示底部临近。比特币自高点跌近50%,恐慌贪婪指数长期处于“极度恐惧”区间;比特币长期持有者占比逼近80%,历史上类似情况常对应市场底部。VC交易活跃度回落至2020年水平,而当时正是新一轮牛市前夜。部分机构如Dragonfly Capital已逆势募资,Blockworks也正低价整合行业资产。历史显示,当多个底部信号共振后,往往孕育着下一轮周期起点。

marsbit19 分鐘前

历史底部信号再现?估值3亿的Messari以1000万贱卖

marsbit19 分鐘前

谷歌TPU出货量,上修50%

近期,多家海外机构上调了谷歌TPU的出货预期,将2027年需求预测从1000万颗上修至1500万颗,增幅达50%。这一变化扭转了市场对算力硬件的保守看法,并带动整条配套产业链需求同步提升。 谷歌TPU采用标准化全光互联架构,硬件配套关系固定。其中,NPO光引擎与TPU芯片按1:1匹配,光模块、OCS光交换、服务器电源、光纤及液冷等环节的需求均随芯片规模增长而确定增加。 液冷成为核心受益方向。因新一代TPU功耗大幅提升,风冷已达物理极限,谷歌集群已全面转向液冷方案。预计2026年为放量元年,下半年开始大规模交付。同时,海外厂商面临技术迭代慢、产能不足的瓶颈,为国产液冷厂商让出替代窗口。凭借快速迭代和稳定交付能力,国内企业正切入谷歌供应链,行业迎来“业绩提速+格局洗牌”的双击行情。预计伴随TPU出货量从2027年的1500万颗增长至2028年的3000-3500万颗,专属液冷市场规模将从千亿级突破至3000亿级。 光纤赛道逻辑亦被重塑。AI算力中心建设催生海量光纤需求,但光纤预制棒扩产周期长,导致供需缺口持续扩大。全球云厂商为锁定货源纷纷签订长期协议,使光纤价格与出货趋稳,摆脱周期性波动。国产光纤凭借产能与成本优势,预计2026年出口量将达2-3亿芯公里,占据全球AIDC需求的半壁江山。 此外,1.6T光模块、OCS光交换、服务器电源等配套环节均将受益于TPU放量,需求持续扩容。投资重心正从芯片算力博弈转向基础设施配套的确定性增量,产业链未来两年业绩确定性进一步增强。

marsbit1 小時前

谷歌TPU出货量,上修50%

marsbit1 小時前

币圈故事退潮后,华尔街真正想要的是什么

币圈故事退潮后,华尔街正将传统金融的核心资产与业务系统性地迁移至区块链上,其目标并非投机或去中心化叙事,而是构建一套可控、生息且合规的链上金融基础设施。 核心动向包括: 1. **资产代币化**:以贝莱德的BUIDL基金为例,它将短期美国国债等低风险资产代币化,提供链上即时结算与每日复投,成为链上金融的基石资产。过户代理机构Securitize即将上市,并与纽交所合作,旨在建立全天候的链上股票清算系统。 2. **波动率变现**:针对比特币等波动资产,贝莱德、高盛等机构推出备兑看涨期权ETF(如BITA),通过系统性卖出期权将波动转化为稳定的月度现金收益,将其包装为标准化的生息产品,以吸引传统大型资金。 3. **稳定币支付与清算**:稳定币正被定位为高效的支付与结算工具。Stripe支持商户用稳定币收款,万事达卡升级系统支持稳定币进行跨时区清算,连SWIFT也计划推出基于分布式账本的跨境清算方案,旨在释放被冻结的巨额结算准备金,提升效率。 4. **监管与合规驱动**:美国《GENIUS法案》等监管框架将合规稳定币明确定义为“支付工具”(禁止派息)并纳入强监管,使其成为美元金融体系的可编程延伸。 总之,华尔街正利用区块链技术的可编程性与效率,在链上复制并优化国债、期权、清算网络等传统金融产品与服务,每一步都紧密依托美元信用与现有监管体系,旨在打造一个更高效且由其主导的新金融管道。

marsbit1 小時前

币圈故事退潮后,华尔街真正想要的是什么

marsbit1 小時前

交易

現貨
合約
活动图片