The post Bitrefill Says Lazarus Group Behind Platform Cyberattack appeared on BitcoinEthereumNews.com. Following an investigation, Bitrefill has accused the LazarusThe post Bitrefill Says Lazarus Group Behind Platform Cyberattack appeared on BitcoinEthereumNews.com. Following an investigation, Bitrefill has accused the Lazarus

Bitrefill Says Lazarus Group Behind Platform Cyberattack

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • Following an investigation, Bitrefill has accused the Lazarus Group of attacking its platform.
  • Bitrefill says the attack details are consistent with the group’s operational pattern.
  • Hackers accessed 18,500 purchase records on Bitrefill, exposing user data.

Bitrefill, a crypto e-commerce and gift card platform, has accused the state-sponsored North Korean hacking apparatus, Lazarus Group, of being behind its cyberattack earlier this month.

A Consistent Pattern With Lazarus Group’s Operations

In a post on X, the cryptocurrency platform said the indicators it observed during its investigation of the attack are consistent with previous attacks carried out by the group. According to Bitrefill, the modus operandi, malware used, on-chain tracing, and reused IP/email addresses were similar to those deployed by the Lazarus Group against other companies in the crypto industry.

In the meantime, Bitrefill confirmed that hackers drained some of the company’s hot wallets on March 1 and made suspicious purchases with its vendors. The crypto firm did not state the amount lost during the attack. However, it confirmed that the hackers accessed 18,500 purchase records, potentially revealing “limited customer information,” such as email addresses, crypto payment addresses, and metadata with IP addresses.

How it Happened

Bitrefill’s report shows that the hackers breached its system through an employee’s laptop, from which they exfiltrated legacy credentials. Subsequently, they used the stolen information to access a snapshot containing production secrets before escalating their access to broader infrastructure, including parts of the company’s database and certain cryptocurrency wallets. In the meantime, Bitrefill said it has contacted about 1,000 users whom it found to be at high risk of having their encrypted customer names potentially revealed.

North Korea’s Threat to Cryptocurrency Security

According to Chainalysis’s estimation, the Democratic People’s Republic of Korea (DPRK) is the biggest and most active threat to crypto security. The blockchain analytics platform estimated that DPRK-linked entities, such as Lazarus Group, along with individuals, stole a record $2.02 billion via crypto thefts in 2025. That includes the highest-ever single crypto exploit by volume, the $1.5 billion stolen from Bybit by the Lazarus Group.

Meanwhile, Bitrefill has informed users about ongoing efforts by the team, in collaboration with industry security researchers, incident response specialists, on-chain analysts, and law enforcement, to understand what happened and how to prevent it from happening again.

Related: North Korea’s Lazarus Group Linked to $37M Upbit Hack, Timing Clashes with $10B Naver Deal

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/bitrefill-accuses-north-korea-linked-lazarus-group-of-hacking-its-platform/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XAG/USD struggles near $75.50 on firm hopes of Fed’s extended pause

XAG/USD struggles near $75.50 on firm hopes of Fed’s extended pause

The post XAG/USD struggles near $75.50 on firm hopes of Fed’s extended pause appeared on BitcoinEthereumNews.com. Silver price (XAG/USD) struggles to gain ground
Share
BitcoinEthereumNews2026/03/19 14:04
Saudi Awwal Bank Adopts Chainlink Tools, LINK Near $23

Saudi Awwal Bank Adopts Chainlink Tools, LINK Near $23

The post Saudi Awwal Bank Adopts Chainlink Tools, LINK Near $23 appeared on BitcoinEthereumNews.com. SAB adopts Chainlink’s CCIP and CRE to expand tokenization and cross-border finance tools. SAB and Wamid target $2.32T Saudi capital markets with blockchain-based tokenization plans. LINK price falls 2.43% to $22.99 despite higher trading volume and steady liquidity ratios. Saudi Awwal Bank has added Chainlink’s Cross-Chain Interoperability Protocol (CCIP) and the Chainlink Runtime Environment (CRE) to its digital strategy. CCIP links assets and data across multiple blockchains, while CRE provides banks with a controlled framework to test and deploy new financial applications. The lender, with more than $100 billion in assets, is applying the tools to tokenized assets, cross-border settlement, and automated credit platforms. The move signals that Chainlink’s infrastructure is being adopted at scale inside regulated finance. Related: Chainlink’s Deal with SBI Is a Major Win, But Chart Shows LINK’s Battle at $27 Resistance Wamid Partnership Aims at $2.32 Trillion Markets In parallel, SAB signed an agreement with Wamid, a subsidiary of the Saudi Tadawul Group, to pilot tokenization of the Saudi Exchange’s $2.32 trillion capital markets. The focus is on equities and debt products, opening the door for blockchain-based issuance and settlement. SAB has already executed the world’s first Islamic repo on distributed ledger technology, in collaboration with Oumla earlier this year. That transaction gave regulators a template for compliant on-chain contracts. The Wamid deal builds directly on that precedent, shifting from single-instrument pilots toward broader capital markets integration. Saudi Blockchain Buildout Gains Pace Saudi institutions are building multiple layers of digital infrastructure. Oumla is working with Avalanche to develop the Kingdom’s first domestically hosted Layer 1 blockchain. SAB’s Chainlink adoption adds an interoperability and execution layer on top. Together, these projects are shaping a domestic framework for tokenization, with global connectivity added only where liquidity requires it. LINK Price and Liquidity Snapshot While institutional adoption progresses, Chainlink’s…
Share
BitcoinEthereumNews2025/09/18 08:49
WLFI Price Drops 4% Despite New Governance Proposal

WLFI Price Drops 4% Despite New Governance Proposal

The post WLFI Price Drops 4% Despite New Governance Proposal appeared on BitcoinEthereumNews.com. Key Highlights World Liberty Financial (WLFI) price dropped by
Share
BitcoinEthereumNews2026/03/19 14:19