September 8, 2026
Atlas21
ITA
podcast
news interviews learn feature industry opinion
Atlas21 B2B

Menu

Main categories

news interviews learn feature industry opinion

Secondary destinations

podcast Atlas21 B2B

Search Atlas21

Atlas21
  • ‎
No Result
View All Result
Atlas21
No Result
View All Result
Atlas21
Home Bitcoin

Bitrefill hit by hacker attack: the Lazarus Group is believed to be behind it

Newsroom by Newsroom
March 17, 2026
in Bitcoin
address poisoning
Share on FacebookShare on TwitterShare on Linkedin

The North Korean group is suspected to be behind the cyberattack that drained wallets and compromised 18,500 transactions on the Bitcoin e-commerce platform.

On March 1, Bitrefill was targeted by a cyberattack believed to be attributable to the Lazarus Group, a cybercriminal organization linked to the North Korean regime.

March 1st incident report

On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation – including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) – we find many similarities…

— Bitrefill (@bitrefill) March 17, 2026

The breach began through a compromised employee laptop. From that device, the attackers were able to extract outdated credentials, which opened access to a snapshot containing sensitive production data. Once inside, the escalation was rapid.

Starting from the initial credentials, the group expanded its access across the entire corporate infrastructure, penetrating critical portions of the database and reaching operational wallets (hot wallets).

The first warning sign emerged from the analysis of purchasing patterns. The Bitrefill team detected suspicious anomalies in transactions involving certain suppliers: gift card inventory was being systematically exploited. At the same time, funds held in hot wallets were being drained and transferred to addresses controlled by the attackers.

Investigators identified multiple indicators pointing to the Lazarus/Bluenoroff Group, the DPRK’s operational arm in cyberspace. Bitrefill worked closely with cybersecurity experts, incident response specialists, blockchain analysts, and law enforcement to reconstruct the incident and close the vulnerabilities.

Compromised data

Approximately 18,500 purchase transactions were compromised during the breach. The exposed data included email addresses, digital asset payment addresses, and metadata such as users’ IP addresses.

For a subset of around 1,000 transactions – where the purchase of specific products required a name – this data was encrypted in the database. However, given that the attackers may have gained access to the decryption keys, Bitrefill is treating this information as potentially compromised. Affected customers have already been directly notified via email.

Post-attack security measures

The company has implemented a multi-layered cybersecurity reinforcement plan:

  • comprehensive reviews with penetration testing conducted by multiple external experts;
  • further tightening of internal access controls;
  • enhanced logging and monitoring for faster anomaly detection;
  • refinement and continuous testing of incident response and automatic shutdown procedures.

At this time, based on the available information, Bitrefill does not believe any specific action is required from customers. As a general precaution, the company recommends remaining vigilant toward unexpected communications mentioning Bitrefill or digital asset-related topics, which may represent potential phishing or social engineering attempts.

Previous Post

Australia: Senate approves bill on digital asset licensing

Next Post

USA: SEC and CFTC declare that most digital assets are not securities

Latest News

Liquid Network recupera 3.400 BTC dopo l’exploit
Bitcoin

Liquid Network recovers 3,400 BTC after exploit

by Newsroom
September 7, 2026
0

About 598.5 BTC remain with the exploit author after on-chain negotiations and the fix announced by Blockstream.

Read moreDetails
ledger nano s
Bitcoin

Ledger sued over the 2020 Ledger hack

by Newsroom
September 4, 2026
0

The class action seeks damages between $500 million and several billion dollars

Read moreDetails
Coldcard bug, weak seeds generated since 2021: “Funds are at risk, move them now”
Bitcoin

Coldcard documents generation of new seeds

by Newsroom
September 4, 2026
0

Recommended versions require device entropy and a user contribution

Read moreDetails
River stima fino a 5.300 miliardi di afflussi in Bitcoin
Bitcoin

River estimates up to $5.3 trillion in Bitcoin inflows

by Newsroom
September 4, 2026
0

The model puts Bitcoin at up to $840,000 within five years, combining three assumptions: 40% of portfolios involved, an average...

Read moreDetails
Aerial shot of historic university buildings with lush green landscapes and clear skies
Bitcoin

Cornell publishes Bitcoin adoption index

by Newsroom
September 3, 2026
0

The survey includes 25,880 interviews across 25 countries

Read moreDetails
Atlas21

© 2026 Atlas21

Navigate Site

  • Editorial Policy
  • Cookie Policy
  • Privacy Policy
  • Team
  • Podcast
  • Home redesign preview

Follow Us

Atlas21
News Interviews Learn Feature Industry Opinion Podcast Atlas21 B2B

Social

X Instagram Nostr LinkedIn YouTube

Contact us

[email protected] Privacy Cookie

The rabbit hole has no bottom.

© 2026 Atlas21. All rights reserved.

No Result
View All Result
  • Bitcoin 101
    • What Is Bitcoin? A Complete Guide
    • Bitcoin Security: A Complete Guide
    • Bitcoin Privacy: A Complete Guide
    • Lightning Network: A Complete Guide
    • Bitcoin Mining: A Complete Guide
    • Advanced Bitcoin: A Technical Guide
  • Learn
  • Latest News
  • Interviews
  • Opinion
  • Feature
  • Podcast
  • B2B Services
  • About Us
  • Contacts

© 2026 Atlas21

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site, we will assume that you are happy with it.