The post Bitrefill says attack shows Lazarus Group patterns after hot wallets drained appeared on BitcoinEthereumNews.com. Bitrefill has disclosed details of a The post Bitrefill says attack shows Lazarus Group patterns after hot wallets drained appeared on BitcoinEthereumNews.com. Bitrefill has disclosed details of a

Bitrefill says attack shows Lazarus Group patterns after hot wallets drained

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Bitrefill has disclosed details of a cyberattack on 1 March 2026, revealing that attackers drained funds from its hot wallets and accessed parts of its internal infrastructure. 

The company said its investigation identified multiple similarities with past operations linked to the Lazarus Group. However, it stopped short of definitively attributing the attack.

The breach was detected after Bitrefill observed unusual purchasing patterns tied to its supplier network, alongside unauthorized transfers from its wallets. The company immediately took its systems offline to contain the incident.

Attack began with compromised employee device

According to Bitrefill, the intrusion originated from a compromised employee’s laptop, which allowed attackers to extract a legacy credential. 

That credential provided access to a snapshot containing production secrets, enabling the attackers to escalate privileges across parts of the company’s infrastructure.

From there, the attackers gained access to internal systems, database segments, and certain cryptocurrency wallets. This ultimately led to fund movements and operational disruptions.

Hot wallets drained as supply channels exploited

Bitrefill said the attackers exploited both its gift card inventory system and crypto infrastructure. 

Suspicious purchasing activity revealed that supply lines were being abused, while hot wallets were simultaneously drained and funds moved to attacker-controlled addresses.

The company did not disclose the total value of funds lost. Still, it confirmed that the breach impacted both its e-commerce operations and wallet balances.

18,500 records accessed, limited data exposure

Database logs showed that approximately 18,500 purchase records were accessed during the breach. The exposed data included:

  • Email addresses
  • Crypto payment addresses
  • Metadata such as IP addresses

For around 1,000 purchases, customer names were included. While this data was encrypted, Bitrefill said the attackers may have accessed the encryption keys and is treating it as potentially exposed.

Affected users in this category have already been notified.

The company emphasized that there is no evidence of a full database extraction, noting that the queries appeared limited and exploratory.

Lazarus-linked patterns flagged in investigation

Bitrefill said its investigation—based on malware analysis, on-chain tracing, and reused infrastructure such as IP and email addresses—revealed similarities with known tactics used by the Lazarus Group and its associated unit, Bluenoroff.

While attribution remains cautious, the overlap in modus operandi and tooling suggests the attack may align with previous campaigns targeting crypto companies.

Systems restored as operations normalize

Following the incident, Bitrefill worked with external cybersecurity firms, on-chain analysts, and law enforcement to contain the breach and restore operations. Most services, including payments and product availability, have since returned to normal.

The company said it remains financially stable and will absorb the losses from operational capital. It also outlined steps taken post-incident, including:

  • Strengthened access controls
  • Expanded monitoring and logging
  • Additional security audits and penetration testing

Bitrefill added that customer data was not the primary target and, based on current findings, users do not need to take specific action beyond remaining cautious of suspicious communications.


Final Summary

  • Bitrefill confirmed a cyberattack that drained hot wallets and exposed limited user data, with the investigation pointing to similarities with the tactics of the Lazarus Group.
  • The incident highlights ongoing security risks in crypto infrastructure, particularly from sophisticated, state-linked threat actors targeting operational weaknesses.

Source: https://ambcrypto.com/bitrefill-says-attack-shows-lazarus-group-patterns-after-hot-wallets-drained/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

James Gunn’s ‘Superman’ Coming To HBO Max This Week

James Gunn’s ‘Superman’ Coming To HBO Max This Week

The post James Gunn’s ‘Superman’ Coming To HBO Max This Week appeared on BitcoinEthereumNews.com. David Corenswet in “Superman.” Warner Bros. Pictures Superman, director James Gunn’s Man of Steel tale starring David Corenswet, Rachel Brosnahan and Nicholas Hoult, is coming to HBO Max this week. Rated PG-13, Superman opened in theaters on July 11 before arriving on digital streaming via premium video on demand on Aug. 15. The official summary for the movie reads, “When Superman (Corenswet) is drawn into conflicts both abroad and at home, his actions to protect humankind are questioned, and his vulnerability allows tech billionaire and master deceiver Lex Luthor (Hoult) to leverage the opportunity to get Superman out of the way for good. Forbes‘The Fantastic Four: First Steps’ Gets Streaming DateBy Tim Lammers “Will the Daily Planet’s intrepid reporter Lois Lane (Brosnahan), together with the aid of Metropolis’s other metahumans and Superman’s own four-legged companion, Krypto, be able to help Superman before Luthor can completely destroy him?” Warner Bros. Discovery announced earlier this week that Superman will begin streaming on HBO Max on Friday, Sept. 19, and debut on cable on HBO linear on Saturday, Sept. 20, at 8 p.m. ET. HBO Max will also stream a version of Superman using American Sign Language, which will be interpreted by deaf ASL interpreter Giovanni Maucere and directed by Leila Hanaumi (Barbie with ASL, The Last of Us with ASL), the streaming platform noted. Forbes‘South Park’ Season 27 Updated Release Schedule: When Do New Episodes Come Out?By Tim Lammers HBO Max offers an ad-based tier that costs $9.99 per month and an ad-free tier that $16.99 per month. Additionally, an ad-free tier with 4K Ultra HD programming costs $20.99 per month. How Did ‘Superman’ Perform In Theaters? Superman has earned $353.9 million domestically and $261.2 internationally for a worldwide box office tally of $615.1 million to date. The film had a production…
Share
BitcoinEthereumNews2025/09/18 20:38
Neom terminates $1bn tunnel contract at heart of The Line

Neom terminates $1bn tunnel contract at heart of The Line

Saudi Arabia’s Neom has cancelled a roughly $1 billion tunnelling contract at the heart of its flagship “The Line” giga-project, according to public documents.
Share
Agbi2026/03/18 11:28
SEC says most crypto assets are not securities in new regulatory framework

SEC says most crypto assets are not securities in new regulatory framework

The post SEC says most crypto assets are not securities in new regulatory framework appeared on BitcoinEthereumNews.com. The U.S. Securities and Exchange Commission
Share
BitcoinEthereumNews2026/03/18 11:27