Bitrefill said attackers linked to North Korea's Lazarus Group breached the cryptocurrency gift card platform on March 1 by first compromising an employee laptop, stealing a legacy credential, and using it to access a snapshot containing production secrets. The intrusion expanded into broader infrastructure, including parts of the database, production keys, and cryptocurrency wallets, and was detected after the company observed suspicious purchasing patterns indicating abuse of its gift card inventory and supplier channels.
The company said the attackers drained funds from some hot wallets and accessed about 18,500 purchase records containing email addresses, crypto payment addresses, IP addresses, and related metadata; roughly 1,000 records also included encrypted usernames. Bitrefill attributed the incident using a combination of malware analysis, TTPs, IP and email overlaps, and blockchain tracing, notified affected users, restored operations after taking systems offline, and said it would absorb losses from operational capital, though it did not disclose the total amount stolen.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, Bitrefill said it notified affected users, would absorb losses through operational capital, and began working with incident responders, security researchers, on-chain analysts, and law enforcement while strengthening access controls, monitoring, and testing.
Bitrefill publicly announced the March 1 breach on social media on Tuesday, saying the incident exposed roughly 18,500 purchase records and attributing the attack to North Korea-linked Lazarus Group based on malware, infrastructure, email addresses, and blockchain tracing.
Bitrefill said it restored its website and app on 2026-03-05 after containment and recovery efforts. The company continued gradually resuming services while investigating the breach.
After detecting unusual supplier purchasing patterns and hot-wallet draining activity during the intrusion, Bitrefill took systems offline to contain the incident. The attack exposed about 18,500 purchase records and involved abuse of gift card inventory and supply lines.
On 2026-03-01, attackers gained initial access to Bitrefill through a compromised employee laptop, used a legacy credential to reach production secrets, and expanded into parts of the company's infrastructure, database, and some cryptocurrency wallets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcenknews.org
Open sourcetherecord.media
Open sourcecoindesk.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.