-
The way the hackers acted had similarities to previous attacks on other companies.
-
The attackers accessed approximately 18,500 purchase records.
After an exhaustive technical investigation, the bitcoin (BTC) top-up platform, Bitrefill, issued a detailed report on the security incident that occurred on March 1, 2026.
Findings suggest attack linked to the North Korean group Lazarus/Bluenoroffknown for its offensives against the digital asset sector.
«Based on the indicators observed during the investigation, including the modus operandi, the malware used, the chain trace, and the reused IP and email addresses, we found many similarities between this attack and previous cyberattacks perpetrated by the North Korean group Lazarus/Bluenoroff against other companies in the cryptocurrency sector,» the company said in its report published 16 days after the incident.
According to Bitrefill, the attack originated by compromising an employee’s laptopallowing the perpetrators to extract an old credential.
Through this initial access, the attackers managed to infiltrate a production snapshot and escalate privileges to the general infrastructure, affecting parts of the database and certain company wallets.

By detecting unusual purchasing patterns and emptying of portfolios, the Bitrefill team activated its containment protocolproceeding to completely disconnect its systems, as reported by NoticiasVE.
Bitrefill emphasized that, due to its privacy-by-design architecture, The impact on users was limited. By not requiring mandatory identity verification processes for most of its services, the platform stores a minimum amount of personal data.
«Based on our investigation and records, we have no reason to believe that customer data was the target of this security breach. There is no evidence that they mined our entire database; «Only, the attackers ran a limited number of queries, typical of a survey, to determine what information they could steal, including cryptocurrencies and Bitrefill’s gift card inventory,» they indicated.
However, in an exercise of transparency, the company confirmed that approximately 18,500 purchase records were accessed. This data includes email addresses, cryptocurrency payment addresses, and connection metadata such as IP addresses.
In approximately 1,000 specific cases where the product required a name, said information was encrypted, the platform says. And they assert that, although there is a possibility that the attackers accessed the encryption keys, Affected customers have already been notified directly.
Bitrefill’s technical evaluation indicates that it is not necessary for users to take additional actions at the moment, although it is recommended to remain vigilant against possible suspicious communications that attempt to impersonate the brand’s identity.
Despite the sophistication of the attack, Bitrefill confirmed that its financial health remains strong. As indicated, the company will absorb the losses with its own operating capital and has restored almost all of its services, including payments and inventories.
«We have already significantly improved our cybersecurity practices, but we are committed to continuing to learn from this experience to ensure that user and business balances and data remain as secure as possible,» the company said.
To prevent future incidents, the platform has strengthened its internal access controls and monitoring systems in collaboration with external security specialists such as ZeroShadow and SEAL Org.