Bitrefill suffers major hack linked to North Korean groups

Bitrefill suffered a cyberattack on March 1, 2026, linked to North Korean groups. Attackers accessed databases and hot wallets, exposing 18,500 records. Bitrefill restored services and strengthened security.

Bitrefill, a leading cryptocurrency e-commerce platform, experienced a sophisticated cyberattack on March 1, 2026. Evidence suggests the breach was orchestrated by North Korean-linked hacking groups Lazarus and Bluenoroff. The incident began when attackers compromised an employee's laptop, leveraging legacy credentials to access production systems, parts of the database, and certain cryptocurrency hot wallets. Approximately 18,500 purchase records were partially exposed, including email addresses and crypto payment information. A subset of these records also contained customer names. The attackers exploited gift card inventories and supplier purchasing lines, resulting in the theft of funds from hot wallets. Bitrefill detected the breach through irregular purchasing patterns and responded by taking systems offline, launching a forensic investigation, and notifying affected users. Most services have since been restored, and the company is absorbing operational losses while implementing enhanced security measures. Bitrefill emphasized that customer data was not the main target and that no full database exfiltration occurred.

Related News