LIVE NEWS
  • MP grills Parliament over fish deaths in dyke
  • Trump Makes Pearl Harbor Joke In Meeting With Japan’s Prime Minister
  • Gum disease bacterium linked to breast cancer growth and spread
  • Today’s NYT Mini Crossword Answers for March 20
  • Trump invokes Pearl Harbor in front of Japanese prime minister to defend Iran attack secrecy
  • Visa prepares payment systems for AI agent-initiated transactions
  • King opens world’s longest managed coastal walk – but much of it is still closed off | Walking
  • Rightwing narrative fuelling false belief UK public oppose net zero, study finds | Green politics
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Crypto»Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups
Crypto

Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups

primereportsBy primereportsMarch 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups
Share
Facebook Twitter LinkedIn Pinterest Email


In brief

  • Bitrefill was hit by a March 1 cyberattack that escalated from a compromised laptop to database and wallet access, with evidence pointing to North Korean hacking groups Lazarus and Bluenoroff.
  • About 18,500 purchase records were partially exposed; no full database exfiltration occurred, and affected users were notified directly.
  • Most operations have been restored, losses will be covered by operational capital, and Bitrefill is tightening security measures going forward.

Bitrefill, a platform that lets users exchange cryptocurrency for gift cards and phone service credit, disclosed Tuesday that it was targeted in a March 1 cyberattack.

According to the firm, it began with a compromised employee laptop, then expanded into broader infrastructure after attackers exfiltrated a legacy credential tied to a snapshot containing production secrets.

In an incident report posted to X, the company said the attackers moved from initial access into parts of its database and certain cryptocurrency wallets, while also exploiting gift card inventory and supplier purchasing lines. Bitrefill said it detected the breach after spotting suspicious supplier purchasing patterns. Once confirmed, it took all systems offline as part of containment.

The company had previously disclosed on March 1 that it was dealing with a “technical issue” and then later a “security issue,” at which point it took down all services. Tuesday was the first time that Bitrefill provided full details on the attack and potential instigators.

March 1st incident report

On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation – including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) – we find many similarities…

— Bitrefill (@bitrefill) March 17, 2026

The company said its investigation found multiple indicators that it described as similar to prior industry attacks from the North Korean state-sponsored hacking groups Lazarus and Bluenoroff, including malware patterns, on-chain tracing, and reused infrastructure. Bitrefill said it has been working with incident responders, on-chain analysts, and law enforcement as the investigation continues.

On customer impact, Bitrefill said logs show no evidence of full database exfiltration, but a subset of records was accessed. The company said approximately 18,500 purchase records were affected, including limited fields such as email addresses, crypto payment addresses, and metadata including IP addresses.

For roughly 1,000 purchases requiring customer names, Bitrefill said those fields were encrypted but is treating them as potentially accessed because attackers may have obtained relevant keys. The company said users in that subset were notified directly by email.

Bitrefill said it does not require mandatory KYC and stores verification information with an external provider, rather than in internal backups. Based on current findings, the company said it does not believe customers need to take specific action, while advising caution around unexpected Bitrefill- or crypto-related communications.

The company said most operations are now back to normal, including payments, stock, and accounts, and that losses will be absorbed through operational capital. Bitrefill also said it is continuing external security reviews and penetration testing, tightening internal access controls, and upgrading logging, monitoring, and incident-response automation.

North Korean hacking groups have been tied by authorities to many prominent crypto industry heists, including last year’s $1.4 billion Bybit exchange hack, and 2022’s $622 million hack of the Ronin gaming network tied to crypto game Axie Infinity. Last year, hackers linked to North Korea swiped over $2 billion worth of crypto, per a report from Chainalysis.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCTG unveils cyber resilience scoring dashboard for measurable risk reduction
Next Article Iran expert says Trump’s ‘war of choice’ has morphed into a ‘war of necessity’ : NPR
primereports
  • Website

Related Posts

Crypto

Retail power gold’s rise, while Bitcoin attracts fresh institutional interest

March 19, 2026
Crypto

Stablecoin Bill Enters Final Stage — Yield Rules and DeFi Are on the Line

March 19, 2026
Crypto

Pi Network bucks crypto market crash as major mainnet upgrade fuels hype

March 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • MP grills Parliament over fish deaths in dyke
  • Trump Makes Pearl Harbor Joke In Meeting With Japan’s Prime Minister
  • Gum disease bacterium linked to breast cancer growth and spread
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.