Bitrefill Discloses Cyberattack, Points to North Korea’s Lazarus Group

Bitcoins

Crypto e-commerce platform Bitrefill said it was the target of a cyberattack earlier this month that resulted in stolen funds and limited exposure of customer data, with indicators pointing to the North Korean-linked Lazarus Group as a likely perpetrator.

The breach, which began on March 1, originated from a compromised employee laptop, according to the company’s incident report. 

Attackers were able to extract legacy credentials tied to production systems, allowing them to escalate access across Bitrefill’s infrastructure, including segments of its internal database and certain cryptocurrency hot wallets.

Bitrefill said the attackers drained an undisclosed amount of funds from its hot wallets while also exploiting its gift card inventory systems to place suspicious purchases with vendors. The company did not specify the total financial impact but stated it will absorb the losses using operational capital.

The intrusion was first detected through irregular purchasing patterns and anomalies in supplier activity. 

In response, Bitrefill temporarily took its systems offline to contain the breach across its global operations. The company said services, including payments and account access, have since returned to normal levels.

As part of the attack, approximately 18,500 purchase records were accessed. The exposed data includes email addresses, cryptocurrency payment addresses and metadata such as IP addresses. 

Around 1,000 of those records involved encrypted customer names, which are being treated as potentially exposed due to the possibility that attackers accessed encryption keys. Bitrefill said it has notified affected users directly.

Despite the breach, the company emphasized that it stores minimal personal data and does not require mandatory know-your-customer verification for most transactions. Any KYC-related information is handled by external providers and is not stored within Bitrefill’s systems. The firm added there is no evidence that its full database was exfiltrated or that customer data was the primary target.

“Based on our investigation and logs, we don’t have reason to think that customer data was the objective,” the company said, noting that the attackers appeared to conduct limited queries consistent with probing for valuable assets such as cryptocurrency holdings and gift card inventory.

Bitcoins North Korea’s Lazarus Group was involved

Bitrefill cited several indicators linking the attack to the Lazarus Group, including similarities in malware, reused infrastructure such as IP addresses and email accounts, and on-chain transaction patterns. 

The group, often associated with North Korea, has been tied to some of the largest crypto thefts in recent years through its specialized subgroup, Bluenoroff.

Cybersecurity firms including zeroShadow, SEAL911 and RecoverisTeam assisted in the response and investigation, alongside on-chain analysts and law enforcement. The company said it is implementing additional security measures, including expanded monitoring systems and internal controls, to prevent similar incidents.

The attack highlights ongoing concerns around state-sponsored cyber threats in the digital asset sector. 

According to blockchain analytics firm Chainalysis, groups linked to North Korea were responsible for more than $2 billion in crypto thefts in 2025, accounting for a significant share of total illicit activity in the space.

Bitrefill said operations have stabilized following the incident and expressed confidence in its recovery, noting that customer activity and sales volumes have returned to typical levels.

bitcoins Micah Zimmerman

Micah Zimmerman

Micah first discovered Bitcoin in 2018 but remained a skeptic on the sidelines for too long. Since 2021, he has covered crypto and business and now works as a news reporter for Bitcoin Magazine, based in North Carolina.

Micah Zimmerman Read More

Latest

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

Study suggests fibroid rates in Latina women may be lower than previously thought

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

Rimas Entertainment Presents SONAR: ‘A Record Label Where Artists Can Develop with Freedom’

The label's roster includes Cris MJ, Yan Block, Hades66 and more. Jesús Rodríguez, head of label, SONAR SONAR / Rimas Entertainment Español Rimas Entertainment officially unveils SONAR, a record label focused on the development and projection of artists within the Latin music market, Billboard can announce exclusively today (April 29). The initiative is part of

YouTube’s Tuma Basa to Exit as Director of Black Music & Culture

MusicAfter eight years at the streaming giant, the...

Feza – Khanyisa

MusicDOWNLOAD MP3 SONG...

The Vogue Business Funding Tracker

Introducing the Vogue Business Funding Tracker, a running list highlighting the most notable and intriguing investment and M&A activity in fashion and beauty. From emerging disruptors to legacy giants undergoing major changes, we spotlight the deals that are shifting the dynamics of the sectors we cover, including fashion, beauty, tech and sustainability. April 2026 Icicle

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day