Gate News: On March 18, the crypto payment and gift card platform Bitrefill announced that part of its infrastructure and cryptocurrency wallets were attacked by Lazarus, a hacking group linked to North Korea. Approximately 18,500 purchase records were leaked. These records include email addresses, payment addresses, and IP information, with about 1,000 records involving crypto usernames. Affected users have been notified. The company stated it will use operational funds to cover the losses, and operations have fully resumed.
The attack began when an employee’s laptop was compromised, leading to the leak of old credentials. The attackers gained access to Bitrefill’s database and hot wallets and attempted to drain some funds. The platform promptly took systems offline to control the damage. Bitrefill indicated that customer data was not the main target; the attack primarily focused on cryptocurrency holdings and gift card inventory, rather than stealing the entire database.
Lazarus Group has previously attacked projects such as Ronin Network, Harmony’s Horizon Bridge, WazirX, and Atomic Wallet. The methods used in this attack include malware, on-chain tracking, and reused IP and email addresses, closely resembling Lazarus’s past operations.
Bitrefill has implemented multiple security measures, including external penetration testing, enhanced internal access controls, improved log monitoring, and refined incident response procedures and automatic shutdown protocols. The company stated this was its first major attack in over ten years, but it has sufficient funds and strong profitability to withstand losses. Payment, inventory, and account systems have been restored to normal, and sales have returned to stable levels.
The company reminds customers to stay vigilant, watch for suspicious communications related to Bitrefill or cryptocurrencies, and commits to continuously improving security to protect user assets and privacy. (CoinDesk)
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
Zonda Exchange Discloses 4,500 BTC Cold Wallet as Private Keys Remain Untransferred
Zonda, a Polish crypto exchange, revealed a cold wallet with 4,503 BTC amid a withdrawal crisis. CEO Przemysław Kral addressed fund misappropriation allegations and promised legal action against false claims, emphasizing that private keys were never transferred due to the former CEO's disappearance.
GateNews19m ago
The OneCoin Ponzi scheme begins restitution, with the U.S. Department of Justice setting aside $40 million to compensate victims
The OneCoin Ponzi scheme was founded by Ruja Ignatova in 2014, attracting 3.5 million investors and scamming about $4 billion. The U.S. Department of Justice will provide $40 million in compensation for victims, the founder has gone missing, is listed as the FBI’s No. 1 most-wanted fugitive, and the case has prompted cooperation among law enforcement agencies worldwide, resulting in sanctions against several co-conspirators.
ChainNewsAbmedia31m ago
Rhea Finance Suffers Attack, Loses Approximately $7.6M
Rhea Finance experienced a security breach where an attacker created fake token contracts and manipulated liquidity pools, misleading the oracle system and extracting at least $7.6 million in assets.
GateNews1h ago
Ukraine Dismantles International Cybercrime Ring, Seizes $3M in Cryptocurrency
A suspect connected to an international cybercriminal group was arrested in Ukraine for $100 million in fraud and money laundering. Police seized $11 million in assets and $3 million in cryptocurrency. The suspect faces charges for document forgery and money laundering.
GateNews3h ago
DeFi Sector Faces Multiple Pressures as Yields Fall and $285M Hack Raises Security Concerns
Decentralized finance (DeFi) is under pressure as lending yields drop to levels similar to traditional bonds, blockchain activity declines, and a significant hack raises security concerns, challenging claims of institutional-grade safety.
GateNews3h ago
France to Introduce New Measures to Combat Crypto-Related Kidnappings, 41 Cases Reported in 2026
France is implementing new measures to protect cryptocurrency holders in response to rising crime, including a prevention platform and stricter protocols. The country has seen a significant increase in crypto-related kidnappings, leading global incidents.
GateNews5h ago