LIVE NEWS
  • AI costs how much? GitHub Copilot users react to new usage-based pricing system.
  • European Parliament committee votes to scrap US tariffs
  • Hints and Solutions for June 2
  • It has the highest levels of toxic Pfas in drinking water in Scotland. But how did this remote island become awash with forever chemicals? | Pfas
  • For veterans, a place where peace can take root : NPR
  • This common amino acid helped mice survive deadly inflammation
  • Apple Will Reportedly Add Bill-Splitting Feature to iOS 27
  • Opinion | Putin Has No Good Way Out of His War
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Crypto»Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups
Crypto

Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups

primereportsBy primereportsMarch 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups
Share
Facebook Twitter LinkedIn Pinterest Email


In brief

  • Bitrefill was hit by a March 1 cyberattack that escalated from a compromised laptop to database and wallet access, with evidence pointing to North Korean hacking groups Lazarus and Bluenoroff.
  • About 18,500 purchase records were partially exposed; no full database exfiltration occurred, and affected users were notified directly.
  • Most operations have been restored, losses will be covered by operational capital, and Bitrefill is tightening security measures going forward.

Bitrefill, a platform that lets users exchange cryptocurrency for gift cards and phone service credit, disclosed Tuesday that it was targeted in a March 1 cyberattack.

According to the firm, it began with a compromised employee laptop, then expanded into broader infrastructure after attackers exfiltrated a legacy credential tied to a snapshot containing production secrets.

In an incident report posted to X, the company said the attackers moved from initial access into parts of its database and certain cryptocurrency wallets, while also exploiting gift card inventory and supplier purchasing lines. Bitrefill said it detected the breach after spotting suspicious supplier purchasing patterns. Once confirmed, it took all systems offline as part of containment.

The company had previously disclosed on March 1 that it was dealing with a “technical issue” and then later a “security issue,” at which point it took down all services. Tuesday was the first time that Bitrefill provided full details on the attack and potential instigators.

March 1st incident report

On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation – including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) – we find many similarities…

— Bitrefill (@bitrefill) March 17, 2026

The company said its investigation found multiple indicators that it described as similar to prior industry attacks from the North Korean state-sponsored hacking groups Lazarus and Bluenoroff, including malware patterns, on-chain tracing, and reused infrastructure. Bitrefill said it has been working with incident responders, on-chain analysts, and law enforcement as the investigation continues.

On customer impact, Bitrefill said logs show no evidence of full database exfiltration, but a subset of records was accessed. The company said approximately 18,500 purchase records were affected, including limited fields such as email addresses, crypto payment addresses, and metadata including IP addresses.

For roughly 1,000 purchases requiring customer names, Bitrefill said those fields were encrypted but is treating them as potentially accessed because attackers may have obtained relevant keys. The company said users in that subset were notified directly by email.

Bitrefill said it does not require mandatory KYC and stores verification information with an external provider, rather than in internal backups. Based on current findings, the company said it does not believe customers need to take specific action, while advising caution around unexpected Bitrefill- or crypto-related communications.

The company said most operations are now back to normal, including payments, stock, and accounts, and that losses will be absorbed through operational capital. Bitrefill also said it is continuing external security reviews and penetration testing, tightening internal access controls, and upgrading logging, monitoring, and incident-response automation.

North Korean hacking groups have been tied by authorities to many prominent crypto industry heists, including last year’s $1.4 billion Bybit exchange hack, and 2022’s $622 million hack of the Ronin gaming network tied to crypto game Axie Infinity. Last year, hackers linked to North Korea swiped over $2 billion worth of crypto, per a report from Chainalysis.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCTG unveils cyber resilience scoring dashboard for measurable risk reduction
Next Article Iran expert says Trump’s ‘war of choice’ has morphed into a ‘war of necessity’ : NPR
primereports
  • Website

Related Posts

Crypto

Banks Fear Stablecoins as Yield Threatens Deposit Business: Report

June 1, 2026
Crypto

Cardano just canceled is 2026 Summit

June 1, 2026
Crypto

CLARITY Act Stall Means No Crypto Regulation Until 2030

June 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • AI costs how much? GitHub Copilot users react to new usage-based pricing system.
  • European Parliament committee votes to scrap US tariffs
  • Hints and Solutions for June 2
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.