Crypto E-Commerce Platform Bitrefill’s Funds Drained In North Korean Cyberattack

2026-3-18 05:00

Bitrefill, a Sweden-based crypto e-commerce platform, revealed on Tuesday that it fell victim to a cyberattack on March 1, 2026, carried out by suspected North Korean hackers linked to the notorious Lazarus group. 

The company released a post-mortem report detailing the breach, which resulted in drained funds and the exposure of a subset of user data.

18,500 Purchase Records Exposed

In a statement shared on social media platform X, Bitrefill explained that the attack exhibited several indicators consistent with previous incursions attributed to the North Korean Lazarus and Bluenoroff groups. 

The attack was initiated through a compromised employee laptop, from which legacy credentials were extracted. These credentials reportedly allowed the attackers to access sensitive data, including a snapshot containing crucial production secrets, ultimately leading to broader access within Bitrefill’s infrastructure, database, and wallets.

The cyberattack was first detected when the team noticed “suspicious purchasing patterns,” indicating that gift card inventories were being misused. As a result, some of the company’s hot wallets were compromised, with funds being redirected to wallets controlled by the attackers. 

Regarding customer data, Bitrefill emphasized that its investigation did not indicate that customers’ information was the primary target of the breach. 

The firm asserted there is no evidence suggesting the attackers accessed the entire database; rather, they executed a limited number of queries, likely in an attempt to probe the system for valuable data, including cryptocurrency and gift card inventories.

However, the company did confirm that the breach involved access to approximately 18,500 purchase records, which contained limited customer information such as email addresses, cryptocurrency payment addresses, and metadata including IP addresses. 

For around 1,000 purchases, customers had to provide names for specific products, and while this information is encrypted, the attackers may have accessed the encryption keys. 

Bitrefill Strengthens Cybersecurity Post-Attack

In response to the cyberattack, Bitrefill is enhancing its cybersecurity measures. This includes thorough reviews and penetration tests conducted by various external experts, and implementing their recommendations. 

The platform is also tightening internal access controls, improving logging and monitoring for quicker detection, and refining its incident response protocols alongside automated shutdown strategies.

Additionally, Bitrefill has been collaborating with top industry security experts, incident response teams, on-chain analysts, and law enforcement agencies to gain a deeper understanding of the breach and to implement measures that prevent future occurrences. 

In its statement, the firm clarified that operations are returning to normal. Payment processing, stock availability, and account functionalities are stabilizing. The Bitrefill team concluded:

Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital… We will continue to do our best to continue deserving your trust.

Featured image from OpenArt, chart from TradingView.com

origin »

Bitcoin price in Telegram @btc_price_every_hour

Sharpe Platform Token (SHP) на Currencies.ru

$ 0.0004599 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0.0004599 - H: $0.0004599
Капитализация $8.007k Rank 99999
Доступно / Всего 17.41m SHP

korean crypto north cyberattack e-commerce platform bitrefill

korean crypto → Результатов: 126


Фото:

This S. Korean Association Approved 12 Local Exchanges. New Money Expected in the Crypto Markets

Any crypto-enthusiast or crypto-trader who was active around January this year, can attest to the fact that South Korean crypto-trading made up the bulk of the action in the crypto-markets. But as soon as the government officials in the country started hinting at a complete ban on crypto-trading around late January, the crypto-markets were never […] The post This S.

2018-7-14 10:41


Фото:

New Crypto Laws Proposed by Korean Political Parties

South Korea’s National Assembly is reportedly set to witness a whirlwind of legislative efforts around cryptocurrencies in the coming days. Between July 13 and 26, members of a number of Korean political parties are expected to submit bills focused on regulating cryptocurrencies, initial coin offerings and blockchain, according to a report from The Korea Times. While

2018-7-12 23:33


Korean Financial Authorities Draft Policies to Help Grow Crypto Industry

Financial authorities in Korea will ease regulations on crypto-based assets in attempts to line-up with policies brought forth by the G20 nations and foster growth in the industry. Korea Establishes “Unified Regulations” The new polices are “unified regulations” that relate to “all activities” of Korea’s cryptocurrency exchange operators — a country that has a huge.

2018-7-7 00:00


Фото:

South Korea legitimizes Blackheine business with major new classification standards

The South Korean government is drafting major new industry classification standards for the domestic blockchain industry, local crypto news outlet The BChain reports Thursday, July 5. The scheme will reportedly serve as a basis for policy making, notably aimed towards “blockchain promotion and regulatory frameworks,” and covers areas including blockchain systems construction, decentralized applications (DApps)

2018-7-5 19:23


Фото:

Korean Specialists to Test Crypto Exchanges’ Taking care of of Individual Data

Two Korean watchdogs have announced a joint probe into crypto exchange operators’ handling of personal data, local news outlet Chosun reports Monday, July 2. The probe will reportedly check the status of technical and administrative protection measures related to users’ personal data – covering data access control measures, anti-tampering measures, personal data encryption, and malware

2018-7-2 20:12


Contradictory Reports Emerge on Crypto Taxation in South Korea

One of the most controversial topics in the crypto industry, taxation, has yet to be settled by regulators. The industry has been kept guessing what policies regulators will eventually agree on, and with different regions and countries having very different outlooks on cryptocurrency, there is no telling what laws to anticipate. The South Korean crypto […]

2018-6-27 17:00