BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home CRYPTO

Bitrefill Hack Linked to Lazarus Group – Here Is Why Crypto Security Risks Are Rising

Michael Juanico by Michael Juanico
March 17, 2026
in CRYPTO, FINANCE, OPINION
Share on XShare in TelegramShare on Reddit
  • Bitrefill suffered a cyberattack likely tied to North Korea’s Lazarus Group
  • Hackers accessed wallets, infrastructure, and limited customer data
  • The incident highlights growing state-backed threats in crypto

Crypto e-commerce platform Bitrefill has confirmed it was targeted in a cyberattack earlier this month, with strong indicators pointing to North Korea’s Lazarus Group. The attack reportedly began on March 1 and involved tactics, malware, and infrastructure patterns similar to previous operations linked to the group.

According to the company, attackers gained access through a compromised employee laptop, a method commonly used by Lazarus. From there, they were able to drain some hot wallets, interact with vendor systems, and probe internal infrastructure. While the total financial loss has not been disclosed, Bitrefill said it will absorb any damages using its own operational capital.

How the Attack Unfolded

The breach went beyond just wallets. Bitrefill revealed that parts of its broader infrastructure were accessed, including sections of its database and certain crypto systems.

Hackers retrieved around 18,500 purchase records, exposing limited customer data such as email addresses, crypto payment addresses, and metadata like IP information. Roughly 1,000 records may have also revealed encrypted customer names, prompting the company to notify affected users.

Despite this, Bitrefill emphasized that there is no evidence the attackers extracted the full database. The activity appeared more exploratory, aimed at identifying valuable assets like crypto funds and gift card inventory.

Lazarus Group Remains the Biggest Threat

The suspected involvement of Lazarus highlights a growing trend in crypto security. The North Korean-backed group has become one of the most active and successful hacking operations in the space.

In 2025 alone, entities linked to the group were responsible for an estimated $2.02 billion in stolen crypto. That includes major incidents like the $1.5 billion Bybit exploit, one of the largest hacks in the industry’s history.

Their methods have also evolved. Beyond technical exploits, Lazarus is known to infiltrate companies through social engineering, including posing as IT workers to gain internal access.

Limited KYC Exposure but Ongoing Risks

Bitrefill noted that most of its services do not require mandatory KYC, which helped limit the exposure of sensitive personal data. In cases where identity verification is required, the data is handled by external providers rather than stored internally.

This likely reduced the potential damage from the breach. Still, the incident raises ongoing concerns about how crypto companies manage infrastructure access and employee security.

The company has since worked with multiple cybersecurity firms to contain the attack and restore operations. Systems were temporarily taken offline, but services, payments, and sales volumes have now returned to normal.

A Reminder of Structural Risk in Crypto

This attack is another reminder that crypto’s biggest vulnerabilities are often operational, not just technical. Even as blockchain systems themselves remain secure, the surrounding infrastructure continues to be a target.

State-backed actors are increasingly focused on crypto due to its liquidity and global accessibility. As the industry grows, so does the sophistication of these threats.

For users and companies alike, the takeaway is clear. Security is no longer just about wallets and keys, it’s about the entire system surrounding them.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: BitrefillCrypto HackCrypto SecurityCybersecurityLazarusNorth Korea
TweetShareShare
Michael Juanico

Michael Juanico

Michael is a BSBA Management graduate from Mindanao State University and has been a professional content writer since 2019. He began exploring cryptocurrency in 2021 and has since made blockchain and digital assets his primary focus. For nearly four years, Michael has contributed research and editorial content at Aiur Labs and BlockNews, producing clear and accessible coverage of market trends, trading strategies, and project developments. He is transparent about his personal holdings in Bitcoin, TRON, and select meme tokens, combining writing expertise with hands-on market experience to deliver trustworthy insights to readers.

DON'T MISS THESE! HOT OFF THE PRESS

Amazon Just Turned AI Payments Into Infrastructure—And Quietly Rewired How the Internet Gets Monetized
CRYPTO

Amazon Just Turned AI Payments Into Infrastructure—And Quietly Rewired How the Internet Gets Monetized

March 17, 2026
Trump Says NATO Won’t Join Iran War – Here Is Why Crypto Markets Are Watching
CRYPTO

Trump Says NATO Won’t Join Iran War – Here Is Why Crypto Markets Are Watching

March 17, 2026
PayPal Expands PYUSD Stablecoin to 70 Countries – Here Is Why Crypto Payments Are Growing
CRYPTO

PayPal Expands PYUSD Stablecoin to 70 Countries – Here Is Why Crypto Payments Are Growing

March 17, 2026
AI Agents Just Got a Wallet and an Identity—And That Changes Everything About Online Commerce
CRYPTO

AI Agents Just Got a Wallet and an Identity—And That Changes Everything About Online Commerce

March 17, 2026
CFTC Greenlights Phantom Wallet—A Quiet Ruling That Could Redefine Self-Custody and Trading in the U.S.
CRYPTO

CFTC Greenlights Phantom Wallet—A Quiet Ruling That Could Redefine Self-Custody and Trading in the U.S.

March 17, 2026
Shiba Inu Shorts Get Liquidated as Bitcoin Rises – Here Is Why SHIB Is Gaining Momentum
CRYPTO

Shiba Inu Shorts Get Liquidated as Bitcoin Rises – Here Is Why SHIB Is Gaining Momentum

March 17, 2026
Load More

Related News

Bitrefill Hack Linked to Lazarus Group – Here Is Why Crypto Security Risks Are Rising

Bitrefill Hack Linked to Lazarus Group – Here Is Why Crypto Security Risks Are Rising

March 17, 2026
Amazon Just Turned AI Payments Into Infrastructure—And Quietly Rewired How the Internet Gets Monetized

Amazon Just Turned AI Payments Into Infrastructure—And Quietly Rewired How the Internet Gets Monetized

March 17, 2026
Trump Says NATO Won’t Join Iran War – Here Is Why Crypto Markets Are Watching

Trump Says NATO Won’t Join Iran War – Here Is Why Crypto Markets Are Watching

March 17, 2026
PayPal Expands PYUSD Stablecoin to 70 Countries – Here Is Why Crypto Payments Are Growing

PayPal Expands PYUSD Stablecoin to 70 Countries – Here Is Why Crypto Payments Are Growing

March 17, 2026
AI Agents Just Got a Wallet and an Identity—And That Changes Everything About Online Commerce

AI Agents Just Got a Wallet and an Identity—And That Changes Everything About Online Commerce

March 17, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews