{"id":18407,"date":"2026-03-18T06:59:35","date_gmt":"2026-03-18T06:59:35","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/03\/18\/lazarus-group-suspected-in-bitrefill-hack-that-compromised-hot-wallets\/"},"modified":"2026-03-18T06:59:35","modified_gmt":"2026-03-18T06:59:35","slug":"lazarus-group-suspected-in-bitrefill-hack-that-compromised-hot-wallets","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/03\/18\/lazarus-group-suspected-in-bitrefill-hack-that-compromised-hot-wallets\/","title":{"rendered":"Lazarus Group suspected in Bitrefill hack that compromised hot wallets"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2025\/08\/crypto-news-hacker-breach-scam-option01.webp\" \/><\/p>\n<div>\n<p>The notorious Lazarus Group may have been behind a cyberattack on crypto e-commerce store Bitrefill, the firm estimates.<\/p>\n<div id=\"cn-block-summary-block_ade1cdfb368a1587bf51c682d8cc5edd\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Bitrefill linked a March 1 cyberattack to tactics associated with the Lazarus and BlueNoroff groups, after attackers compromised an employee laptop and drained funds from hot wallets.<\/li>\n<li>Around 18,500 purchase records were accessed, though the company said only limited customer information was exposed and there was no evidence of a full database breach.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Detailing the March 1 incident in a Tuesday X <a href=\"https:\/\/x.com\/bitrefill\/status\/2033931580352221656\" target=\"_blank\" rel=\"nofollow\">post<\/a>, the firm said the attackers used malware, on-chain tracing, and reused IP and email infrastructure to drain funds from its hot wallets after compromising an employee\u2019s laptop. Attackers also allegedly accessed around 18,500 purchase records, although this involved only \u201climited customer information.\u201d<\/p>\n<p>\u201cWe find many similarities between this attack and past cyberattacks by the DPRK Lazarus \/ Bluenoroff group against other companies in the crypto industries,\u201d the firm wrote.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>Bitrefill is a crypto e-commerce platform that allows customers to spend digital assets on real-world products and gift cards. It added that the attackers were primarily financially motivated, as there was \u201cno evidence that they extracted our entire database.\u201d<\/p>\n<p>\u201cThe attackers ran a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory,\u201d it added.<\/p>\n<p>Bitrefill did not disclose how much crypto was stolen but said it would absorb the losses from its operational capital.<\/p>\n<p>\u201cWe have already significantly improved our cybersecurity practices, but vow to continue to draw learnings from this experience to make sure user and company balances and data remain maximally safe,\u201d Bitrefill said, adding that all operations were back to normal.<\/p>\n<p>The company has since strengthened its security posture and has contacted law enforcement while working with security firms to investigate and respond to the incident.<\/p>\n<h2 class=\"wp-block-heading\">Lazarus group remains a major threat<\/h2>\n<p>Over the years, the Lazarus Group has been credited with some of the crypto <a href=\"https:\/\/crypto.news\/lazarus-infects-hundreds-software-developers-targeting-solana-and-exodus-crypto-wallets\/\" target=\"_blank\">industry\u2019s largest hacks<\/a>.<\/p>\n<p>One of the biggest attacks involved crypto exchange Bybit, which lost around $1.4 billion last year. The group was also a suspected actor behind the <a href=\"https:\/\/crypto.news\/south-korea-links-30m-upbit-hack-to-north-koreas-lazarus-group\/\" target=\"_blank\">hack of South Korean crypto exchange Upbit<\/a> and UK-registered trading platform <a href=\"https:\/\/crypto.news\/lazarus-23m-crypto-theft-silenced-a-british-start-up\/\" target=\"_blank\">Lykke<\/a>.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/lazarus-group-suspected-in-bitrefill-hack-that-compromised-hot-wallets\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The notorious Lazarus Group may have been behind a cyberattack on crypto e-commerce store Bitrefill, the firm estimates. Summary Bitrefill linked a March 1 cyberattack to tactics associated with the Lazarus and BlueNoroff groups, after attackers compromised an employee laptop and drained funds from hot wallets. Around 18,500 purchase records were accessed, though the company [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":18408,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-18407","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=18407"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18407\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/18408"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=18407"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=18407"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=18407"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=18407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}