No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Bitrefill reports Lazarus-style exploit drained funds and exposed some user data

March 17, 2026
in Crypto
0
Bitrefill reports Lazarus-style exploit drained funds and exposed some user data


Bitrefill, the established crypto-to-gift-card platform, was hit by a sophisticated cyberattack earlier this month that drained company funds and exposed some customer data.

The team disclosed the incident in an X article on Tuesday, saying that it shares strong similarities with operations linked to Lazarus Group, the notorious North Korean cybercrime collective believed to be responsible for billions of dollars in crypto thefts.

According to Bitrefill, the breach happened on March 1, when attackers gained access to an employee’s device and extracted a legacy login credential.

From there, they used that foothold to pull production secrets and move deeper into Bitrefill’s infrastructure, escalating privileges until they reached parts of its database and certain crypto wallets.

Bitrefill first detected the intrusion after noticing unusual purchasing activity from suppliers.

The company discovered that its gift card inventory and supply chains had been exploited alongside wallet drains. Upon identifying the breach, Bitrefill took all systems offline as part of its containment protocol.

“Getting hit by a sophisticated attack sucks (a lot). We’ve been in business for over 10 years, and it’s the first time we’ve been hit this hard. But we survived,” the company stated in its incident report.

Scope of data exposure

The breach affected about 18,500 purchase records, including customer email addresses, crypto payment addresses, and metadata such as IP addresses.

Roughly 1,000 transactions involved products that required customer names. While that information was encrypted, it may have been exposed if attackers accessed the encryption keys. Bitrefill said it has notified affected customers.

The company said customer-held gift cards, store credits, and account balances were not impacted. It also noted that it does not require mandatory know-your-customer checks, and any KYC data submitted for higher purchase limits is handled by an external provider, not stored on its systems.

Investigators found multiple signs linking the attack to the Lazarus Group and its affiliate Bluenoroff, including malware similarities, blockchain tracing patterns, and reused IP and email infrastructure tied to earlier crypto breaches.

Bitrefill said it worked with security firms and law enforcement in responding to the incident.

Bitrefill plans to cover the financial losses caused by the attack using its operational capital. The platform has restored most functions, including payments, inventory, and customer accounts, with sales volumes returning to pre-incident levels.

The company said it is strengthening its security posture through additional penetration testing, tighter access controls, improved logging and monitoring, and updated incident response procedures, including automated shutdown protocols.

Disclosure: This article was edited by Vivian Nguyen. For more information on how we create and review content, see our Editorial Policy.
Editorial Team

Editorial Team

Related Posts

XRP
Crypto

Ex-Ripple Exec Shares What Burning XRP Means, But Does It Influence Price?

March 17, 2026
GSR Acquires Autonomous, Architech in $57M Crypto Deal
Crypto

GSR Acquires Autonomous, Architech in $57M Crypto Deal

March 17, 2026
Revolut, Trust Wallet integration brings instant self-custody crypto buys to EEA
Crypto

Citibank cuts 12‑month Bitcoin and Ethereum targets as U.S. regulatory drag bites

March 17, 2026
Tally shuts down operations amid reduced demand for DAO tools
Crypto

Tally shuts down operations amid reduced demand for DAO tools

March 17, 2026
Crypto, Polymarket
Crypto

Crypto Betting Giant Polymarket Faces Backlash After Users Harass A Reporter

March 17, 2026
World Launches AgentKit to Verify Human-Backed AI Agents Using World ID
Crypto

World Launches AgentKit to Verify Human-Backed AI Agents Using World ID

March 17, 2026
Load More
Next Post
The Fed issues its latest interest rate decision Wednesday. Here's what to expect

The Fed issues its latest interest rate decision Wednesday. Here's what to expect

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Is Berkshire Hathaway Class B Stock a Good Buy? • Benzinga

    0 shares
    Share 0 Tweet 0
  • How World Liberty’s $3.4B USD1 Stablecoin Powers Onchain Lending Markets

    0 shares
    Share 0 Tweet 0
  • MetaMask Partners Ondo Finance to Integrate Tokenized US Stocks, ETFs, Commodities

    0 shares
    Share 0 Tweet 0
  • Tushar Jain: Business development is key for blockchain success, Solana’s technical roadmap is crucial for its future, and Ethereum faces scalability challenges in trading

    0 shares
    Share 0 Tweet 0

Latest News

The Fed issues its latest interest rate decision Wednesday. Here's what to expect

The Fed issues its latest interest rate decision Wednesday. Here’s what to expect

March 17, 2026
0

The Federal Reserve has little choice but to stay on the sidelines this week as it navigates a mix of...

Bitrefill reports Lazarus-style exploit drained funds and exposed some user data

Bitrefill reports Lazarus-style exploit drained funds and exposed some user data

March 17, 2026
0

Bitrefill, the established crypto-to-gift-card platform, was hit by a sophisticated cyberattack earlier this month that drained company funds and exposed...

Nebius’s stock falls on a bond offering. Here’s why investors are sobering up.

Nebius’s stock falls on a bond offering. Here’s why investors are sobering up.

March 17, 2026
0

The neocloud company has new deals with major tech companies, and just announced that it will be taking on debt...

Amazon Is Now Offering One-Hour and Three-Hour Delivery Options in Select Areas

Amazon Is Now Offering One-Hour and Three-Hour Delivery Options in Select Areas

March 17, 2026
0

We may earn a commission from links on this page. Remember when two-day shipping seemed novel? "Wow—I can order this...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.