In brief
- Bitrefill was deed by a March 1 cyberattack that escalated from a compromised laptop to database and wallet access, with grounds pointing to North Korean hacking groups Lazarus and Bluenoroff.
- About 18,500 acquisition records were partially exposed; nary afloat database exfiltration occurred, and affected users were notified directly.
- Most operations person been restored, losses volition beryllium covered by operational capital, and Bitrefill is tightening information measures going forward.
Bitrefill, a level that lets users speech cryptocurrency for acquisition cards and telephone work credit, disclosed Tuesday that it was targeted successful a March 1 cyberattack.
According to the firm, it began with a compromised worker laptop, past expanded into broader infrastructure aft attackers exfiltrated a bequest credential tied to a snapshot containing accumulation secrets.
In an incidental study posted to X, the institution said the attackers moved from archetypal entree into parts of its database and definite cryptocurrency wallets, portion besides exploiting acquisition paper inventory and supplier purchasing lines. Bitrefill said it detected the breach aft spotting suspicious supplier purchasing patterns. Once confirmed, it took each systems offline arsenic portion of containment.
The institution had antecedently disclosed connected March 1 that it was dealing with a “technical issue” and past aboriginal a “security issue,” astatine which constituent it took down each services. Tuesday was the archetypal clip that Bitrefill provided afloat details connected the onslaught and imaginable instigators.
March 1st incidental report
On March 1, 2026, Bitrefill was the people of a cyberattack. Based connected indicators observed during the probe - including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) - we find galore similarities…
— Bitrefill (@bitrefill) March 17, 2026
The institution said its probe recovered aggregate indicators that it described arsenic akin to anterior manufacture attacks from the North Korean state-sponsored hacking groups Lazarus and Bluenoroff, including malware patterns, on-chain tracing, and reused infrastructure. Bitrefill said it has been moving with incidental responders, on-chain analysts, and instrumentality enforcement arsenic the probe continues.
On lawsuit impact, Bitrefill said logs amusement nary grounds of afloat database exfiltration, but a subset of records was accessed. The institution said astir 18,500 acquisition records were affected, including constricted fields specified arsenic email addresses, crypto outgo addresses, and metadata including IP addresses.
For astir 1,000 purchases requiring lawsuit names, Bitrefill said those fields were encrypted but is treating them arsenic perchance accessed due to the fact that attackers whitethorn person obtained applicable keys. The institution said users successful that subset were notified straight by email.
Bitrefill said it does not necessitate mandatory KYC and stores verification accusation with an outer provider, alternatively than successful interior backups. Based connected existent findings, the institution said it does not judge customers request to instrumentality circumstantial action, portion advising caution astir unexpected Bitrefill- oregon crypto-related communications.
The institution said astir operations are present backmost to normal, including payments, stock, and accounts, and that losses volition beryllium absorbed done operational capital. Bitrefill besides said it is continuing outer information reviews and penetration testing, tightening interior entree controls, and upgrading logging, monitoring, and incident-response automation.
North Korean hacking groups person been tied by authorities to galore salient crypto manufacture heists, including past year’s $1.4 cardinal Bybit speech hack, and 2022’s $622 cardinal hack of the Ronin gaming network tied to crypto crippled Axie Infinity. Last year, hackers linked to North Korea swiped over $2 cardinal worthy of crypto, per a study from Chainalysis.
Daily Debrief Newsletter
Start each time with the apical quality stories close now, positive archetypal features, a podcast, videos and more.

1 day ago
4








English (US) ·