Connect with us
DAPA Banner

Crypto World

Bitrefill blames North Korea-linked Lazarus hacker group for compromising 18,500 purchase records

Published

on

Blockchain sleuth ZachXBT alleges Axiom employee conducted insider trading

Cryptocurrency payments and gift card platform Bitrefill has blamed the North Korea-linked hacking group Lazarus for a cyberattack on March 1, 2026, that compromised parts of its infrastructure and cryptocurrency wallets.

The attackers gained access to production keys, transferred funds from hot wallets, and exposed 18,500 purchase records containing emails, payment addresses, and IP addresses.

Approximately 1,000 records included encrypted usernames. Affected users were notified. Operations have resumed, with the company announcing to cover losses from operational capital. The incident underscores the importance of vigilance regarding crypto and on-chain security.

The modus operandi included malware, on-chain tracing and reused IP and email addresses and was similar to previous attacks attributed to North Korea’s Lazarus Group, also known as Bluenoroff, the company said in a detailed report on X.

Advertisement

The Lazarus Group has previously targeted crypto projects including Ronin Network, Harmony’s Horizon Bridge, WazirX, and Atomic Wallet.

How the attack unfolded

It all began with with a compromised employee laptop, which exposed legacy credentials and allowed attackers to access Bitrefill’s broader infrastructure, including parts of its database and cryptocurrency wallets.

The breach quickly became apparent when the company noticed unusual purchasing patterns among certain suppliers, signaling that attackers were exploiting its gift card inventory and supply chains. The firm also noted that attackers were draining some hot wallets and moving funds to their own addresses, following which, the system was taken offline to contain the damage.

“Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial,” the company said in a statement.

Advertisement

Since the incident, Bitrefill has been working with security researchers, incident response teams, on-chain analysts, and law enforcement to investigate the breach.

Customer data impact

Hackers accessed a small set of purchase records, approximately 18,500, containing

Bitrefill said there is no evidence that customer data was a primary target. Its logs indicate that attackers ran a limited number of queries aimed at cryptocurrency holdings and gift card inventory rather than extracting the entire database.

The platform stores minimal personal data and does not require mandatory KYC. A small subset of purchase records, approximately 18,500, was accessed, containing information such as email addresses, crypto payment addresses, and metadata including IP addresses. About 1,000 records contained encrypted names for specific products; the company is treating this data as potentially compromised and has notified affected customers directly by email.

Advertisement

At present, Bitrefill does not believe customers need to take any additional action, though it advises caution regarding unexpected communications related to Bitrefill or cryptocurrency.

Steps to strengthen security

In response to the breach, Bitrefill said it has already strengthened its cybersecurity practices and is working to draw lessons from the incident.

The company outlined several measures, including conducting comprehensive penetration tests with external experts, tightening internal access controls, enhancing logging and monitoring for faster threat detection, and refining incident response procedures and automated shutdown protocols.

Looking forward

Bitrefill acknowledged that this was its first major attack in more than a decade of operation but stressed that it remains well-funded and profitable, capable of absorbing operational losses. Most systems, including payments, stock, and accounts, are back online, with sales volumes returning to normal.

Advertisement

“Getting hit by a sophisticated attack sucks (a lot),” the company said. “But we survived. We will continue to do our best to continue deserving our customers’ trust.”

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

XRP Crypto Falls to $1.31 After Failed Breakout as Liquidity Dries Up

Published

on

xrp logo

XRP Crypto slipped to $1.31 after a hard rejection at $1.35 left traders with little to show from a breakout attempt that briefly looked credible.

The 2% drop is secondary – what matters is the combination of that ceiling rejection and visibly thinning order book depth, a setup that historically precedes sharper directional moves.

The failed push came off a March 31 high of $1.37, with XRP unable to clear $1.40 resistance and grinding lower through a $1.28–$1.33 range ever since.

That recent run toward $1.35 now looks like a distribution zone rather than a launchpad, and the market cap sits at $80.6 billion with 24-hour volume at just $2.01 billion – reduced participation that confirms the liquidity problem is real. The chart now forces a binary question: does $1.28 hold, or does the next support at $1.15 come into play faster than bulls expect?

Advertisement
Xrp (XRP)
24h7d30d1yAll time

Discover: The best pre-launch token sales

XRP Crypto, Reclaim $1.35 or Retreat to $1.15?

XRP Crypto is trading below both its 50-day EMA ($1.38) and 200-day EMA ($1.88), with price pinned inside a descending channel on the 4-hour chart where both the 50-SMA and 200-SMA act as overhead ceiling.

Daily RSI reads 38 – weak momentum, but not yet in oversold territory, which means there’s no technical floor from that indicator alone. MACD is negative and expanding downward, removing any near-term momentum argument.

Advertisement

Key resistances sit at $1.3500; load-bearing supports are $1.3000 and $1.2698. The $1.28 level has held since February, aligning with the 23.6% Fibonacci retracement – below it, holder support thins materially until $1.15.

Source: TradingView

The bull case requires a clean reclaim of $1.35 on volume – not a wick, a close – followed by a hold above the 50-day EMA at $1.38.

That sequence opens $1.45 and, with a catalyst, $1.60 tied to regulatory progress on the CLARITY Act, which carries a 63% probability of passing in 2026 per current prediction markets. Long-term analysts maintain structurally bullish frameworks, but those scenarios require macro conditions – FOMC dovishness, easing geopolitical tensions – that aren’t present right now.

The bear case activates on a confirmed daily close below $1.28. Analysts are flagging $1.15 as the next meaningful support, with more aggressive targets at $0.80 contingent on oil above $100 and Fed rate holds through Q2.

The uncomfortable reality is that XRP is down nearly 30% year-to-date and 64% from its $3.65 all-time high, and every bounce has been sold. The single most important level: $1.28. Hold it and the range stays intact; lose it and $1.15 becomes the next anchor.

Advertisement

Discover: The best crypto to diversify your portfolio with

The post XRP Crypto Falls to $1.31 After Failed Breakout as Liquidity Dries Up appeared first on Cryptonews.

Source link

Advertisement
Continue Reading

Crypto World

South Korea Tightens Crypto Rules with 5-minute Asset Verification Mandate

Published

on

South Korea Tightens Crypto Rules with 5-minute Asset Verification Mandate

South Korea has ordered all crypto exchanges to reconcile their internal ledgers with actual asset holdings every five minutes after an inspection uncovered weaknesses in internal controls.

The directive was announced on Monday by the Financial Services Commission (FSC) after a meeting with top crypto exchanges and the Digital Asset Exchange Alliance (DAXA), during which they discussed the findings of an emergency inspection triggered by the Bithumb payout incident.

The inspection found that three of the country’s five major exchanges were reconciling balances only once every 24 hours, limiting their ability to respond quickly to discrepancies. Systems designed to halt trading during major mismatches were also found to be insufficient, raising concerns about how exchanges would handle large-scale errors.

In February, Bithumb mistakenly distributed 620,000 Bitcoin (BTC) to 249 users during a promotional event. The exchange later announced that it recovered 99.7% of the funds the same day. The remaining 0.3%, 1,788 BTC that had already been sold, was covered using company reserves.

Advertisement

Related: Bithumb seeks to reappoint CEO despite recent controversies: Report

South Korea mandates five-minute asset checks

Under the new measures, exchanges must implement automated ledger-to-wallet reconciliation systems operating on a five-minute cycle. They will also be required to introduce defined criteria for triggering automatic transaction halts in the event of significant discrepancies.

Beyond reconciliation, regulators are pushing for sweeping changes to internal operations. High-risk processes like promotional payouts will require stronger oversight, including third-party cross-checks and multi-level approval systems. Exchanges will also need to separate high-risk accounts and implement automated verification tools for payments.

Top Korean crypto exchanges. Source: CoinGecko

Furthermore, external audits will shift from quarterly to monthly, while disclosures will expand to include detailed asset balances by wallet and ledger.

“The financial authorities and the DAXA plan to complete the rule changes needed to implement the improvement measures within April this year,” the FSC wrote.

Advertisement

Related: South Korean brokerage Korea Investment & Securities eyes Coinone stake: Report

Bithumb delays IPO to post-2028

Last week, Bithumb announced it is now targeting an IPO after 2028, marking another delay from its earlier 2025 plans as it works through restructuring and regulatory pressure. The exchange said it will focus on strengthening accounting policies and internal controls through 2027, following an advisory agreement with Samjong KPMG.

Meanwhile, Naver Financial has also delayed its planned share swap with Dunamu by about three months, now targeting a shareholder vote on Aug. 18 and completion by Sept. 30.

Magazine: South Korea gets rich from crypto… North Korea gets weapons

Advertisement