Bitrefill suffered a cyberattack on March 1st; investigation identified malware, on-chain traces, and reused infrastructure suggesting possible connection to prior incidents.
Security & Exploits ·
On March 1, 2026, Bitrefill disclosed a cyberattack targeting its e-commerce platform. Investigation indicators—including malware signatures, on-chain transaction traces, and reused IP and email infrastructure—led the company to identify similarities with prior attacks attributed to North Korea's Lazarus and Bluenoroff groups. The initial breach stemmed from a compromised employee laptop, from which legacy credentials were stolen and used to access production secrets and broader infrastructure, including database components and certain hot wallets.
Upon detecting suspicious purchasing patterns with suppliers and unauthorized wallet drains, Bitrefill took all systems offline. The attackers had accessed approximately 18,500 purchase records containing limited customer information such as email addresses, crypto payment addresses, and IP metadata. Around 1,000 additional records contained encrypted customer names; the company treats this data as potentially compromised since attackers may have obtained encryption keys. Bitrefill stated it has no evidence that the entire database was extracted, suggesting attackers conducted limited probing of available cryptocurrency and gift card inventory.
The company emphasized that it stores minimal personal data, does not mandate KYC verification, and keeps verified customer information exclusively with an external KYC provider. Bitrefill does not currently recommend specific customer action, though the assessment may change as the investigation continues. The company has engaged incident response specialists, on-chain analysts, and law enforcement to determine prevention measures going forward.