Connect with us
DAPA Banner

Crypto World

Bitrefill blames North Korea-linked Lazarus hacker group for compromising 18,500 purchase records

Published

on

Blockchain sleuth ZachXBT alleges Axiom employee conducted insider trading

Cryptocurrency payments and gift card platform Bitrefill has blamed the North Korea-linked hacking group Lazarus for a cyberattack on March 1, 2026, that compromised parts of its infrastructure and cryptocurrency wallets.

The attackers gained access to production keys, transferred funds from hot wallets, and exposed 18,500 purchase records containing emails, payment addresses, and IP addresses.

Approximately 1,000 records included encrypted usernames. Affected users were notified. Operations have resumed, with the company announcing to cover losses from operational capital. The incident underscores the importance of vigilance regarding crypto and on-chain security.

The modus operandi included malware, on-chain tracing and reused IP and email addresses and was similar to previous attacks attributed to North Korea’s Lazarus Group, also known as Bluenoroff, the company said in a detailed report on X.

Advertisement

The Lazarus Group has previously targeted crypto projects including Ronin Network, Harmony’s Horizon Bridge, WazirX, and Atomic Wallet.

How the attack unfolded

It all began with with a compromised employee laptop, which exposed legacy credentials and allowed attackers to access Bitrefill’s broader infrastructure, including parts of its database and cryptocurrency wallets.

The breach quickly became apparent when the company noticed unusual purchasing patterns among certain suppliers, signaling that attackers were exploiting its gift card inventory and supply chains. The firm also noted that attackers were draining some hot wallets and moving funds to their own addresses, following which, the system was taken offline to contain the damage.

“Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial,” the company said in a statement.

Advertisement

Since the incident, Bitrefill has been working with security researchers, incident response teams, on-chain analysts, and law enforcement to investigate the breach.

Customer data impact

Hackers accessed a small set of purchase records, approximately 18,500, containing

Bitrefill said there is no evidence that customer data was a primary target. Its logs indicate that attackers ran a limited number of queries aimed at cryptocurrency holdings and gift card inventory rather than extracting the entire database.

The platform stores minimal personal data and does not require mandatory KYC. A small subset of purchase records, approximately 18,500, was accessed, containing information such as email addresses, crypto payment addresses, and metadata including IP addresses. About 1,000 records contained encrypted names for specific products; the company is treating this data as potentially compromised and has notified affected customers directly by email.

Advertisement

At present, Bitrefill does not believe customers need to take any additional action, though it advises caution regarding unexpected communications related to Bitrefill or cryptocurrency.

Steps to strengthen security

In response to the breach, Bitrefill said it has already strengthened its cybersecurity practices and is working to draw lessons from the incident.

The company outlined several measures, including conducting comprehensive penetration tests with external experts, tightening internal access controls, enhancing logging and monitoring for faster threat detection, and refining incident response procedures and automated shutdown protocols.

Looking forward

Bitrefill acknowledged that this was its first major attack in more than a decade of operation but stressed that it remains well-funded and profitable, capable of absorbing operational losses. Most systems, including payments, stock, and accounts, are back online, with sales volumes returning to normal.

Advertisement

“Getting hit by a sophisticated attack sucks (a lot),” the company said. “But we survived. We will continue to do our best to continue deserving our customers’ trust.”

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

RedotPay Defends Team Consolidation After Executive Turnover Report

Published

on

RedotPay Defends Team Consolidation After Executive Turnover Report

Hong Kong-based stablecoin payments company RedotPay said it has “consolidated” teams to improve efficiency as it scales, after a report claimed executive turnover and sensitivities tied to its mainland China connections.

On Wednesday, a Bloomberg report claimed RedotPay is facing leadership churn and sensitivities tied to China as it explores raising up to $150 million. Citing people familiar with the matter, the report said that at least five senior hires left the stablecoin company within a year, including two compliance chiefs, and described a demanding work culture with extended hours.

In February, Bloomberg reported that RedotPay is considering a US IPO that could raise over $1 billion and value the company at more than $4 billion. The Hong Kong-based firm was reported to be working with JPMorgan, Goldman Sachs and Jefferies on a potential New York listing that could take place as early as this year.

“As we transition from an early-stage startup to a unicorn, we are evolving our organizational structure and talent pool to support our ongoing growth trajectory,” RedotPay said in a statement to Cointelegraph without addressing Bloomberg’s claims. The company said that all co-founders, including CEO Michael Gao, the chief operating officer and the chief technology officer, continue to lead key functions.

Advertisement

RedotPay says no urgent need for fundraising

The company confirmed that it has not yet appointed a chief financial officer, noting that one of its co-founders currently oversees finance, alongside its investor relations and corporate development leadership. “We may appoint a CFO at a later stage as the need arises,” the company said, adding that it now employs more than 250 people globally, most of them based in Hong Kong.

Related: Theo closes $100M facility backing gold-linked yield stablecoin

RedotPay also said there is “no urgency” to secure new funding, citing strong operating cash flow and liquidity. The company added that it remains open to investors.

The stance comes after a year of heavy fundraising, with the company raising a total of $194 million across three rounds in 2025. It began with a $40 million Series A in March led by Lightspeed, followed by a $47 million strategic round in September that brought in Coinbase Ventures and helped push the company to unicorn status.

Advertisement
Stablecoin market cap rises above $300 billion. Source: DefiLlama

The momentum continued in December with a $107 million Series B led by Goodwater Capital, alongside investors including Pantera Capital, Blockchain Capital and Circle Ventures.

Founded in 2023, RedotPay offers an app paired with a Visa card that allows users to spend stablecoins in everyday transactions, alongside yield and remittance services.

Related: Standard Chartered sticks to $2T stablecoin call but trims T-bill impact