BlocktoBlockto

Trending

Bitrefill Hack Linked to Lazarus Group Exposes 18,500 Records
NEWS

Photo: Illustrative

Bitrefill Hack Linked to Lazarus Group Exposes 18,500 Records

Crypto payments platform Bitrefill has attributed a March 1 cyberattack to the Lazarus Group, resulting in compromised infrastructure and exposed customer data. The breach led to unauthorized access to production keys, allowing attackers to drain funds from hot wallets and retrieve approximately 18,500 purchase records. These records included email addresses, crypto payment details and IP-related metadata, while around 1,000 entries contained encrypted usernames.

Tristan R.
By Tristan R.

Senior Author · March 18, 2026

2 min
Key takeaways
Crypto payments platform Bitrefill has attributed a March 1 cyberattack to the Lazarus Group , resulting in compromised infrastructure and exposed customer data.
The breach led to unauthorized access to production keys, allowing attackers to drain funds from hot wallets and retrieve approximately 18,500 purchase records.
These records included email addresses, crypto payment details and IP-related metadata, while around 1,000 entries contained encrypted usernames.

Crypto payments platform Bitrefill has attributed a March 1 cyberattack to the Lazarus Group, resulting in compromised infrastructure and exposed customer data. The breach led to unauthorized access to production keys, allowing attackers to drain funds from hot wallets and retrieve approximately 18,500 purchase records. These records included email addresses, crypto payment details and IP-related metadata, while around 1,000 entries contained encrypted usernames.

The incident began with a compromised employee laptop, which exposed legacy credentials and enabled attackers to infiltrate internal systems. Once inside, the attackers exploited supply chains linked to gift card inventory and initiated suspicious transactions, prompting the company to take systems offline to limit further damage.

Limited Data Extraction but Ongoing Investigation

The company stated that attackers appeared to focus on crypto balances and operational systems rather than extracting its full database. Affected users have been notified, and investigations are ongoing with support from security teams and law enforcement agencies.

Security Upgrades and Operational Recovery Underway

Following the breach, Bitrefill has enhanced monitoring systems, tightened access controls and conducted external security testing. The firm confirmed it will cover financial losses using operational funds, with most services now restored and running normally.

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.