Skip to content
btc Bitcoin $71,361 -3.33% eth Ethereum $2,183 -5.50% usdt Tether $1 -0.01% xrp XRP $1 -4.26% bnb BNB $648 -2.75% usdc USDC $1 0.00% sol Solana $89 -4.63% trx TRON $0 -0.66% figr_heloc Figure Heloc $1 0.49% doge Dogecoin $0 -4.81%

Crypto gift card player Bitrefill reports massive data breach, accuses Lazarus Group

Crypto Gift Card Platform Bitrefill Discloses Hack, Points Finger at North Korean Groups
SHARE THIS ARTICLE

Bitrefill, a prominent name in the crypto gift card space, has admitted to having suffered a data breach incident on March 1. Disclosing details of the incident, the platform said that attackers were able to access 18,500 purchase records which consisted of customer information like email addresses, IP addresses, and crypto wallet addresses.

Founded in 2014, Bitrefill is headquartered in Stockholm, Sweden. It does not have the user login/signup mandate. Instead, it lets users provide a valid mail address, select a crypto payment method, and a generate a wallet address to transfer the purchase payments — all as a guest user.

In its X post, the platform said a malware was used to facilitate the data breach, which resembles the modus operandi of North Korea’s notorious Lazarus group and its specialized subgroup called Bluenoroff.

“The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated. That credential provided access to a snapshot containing production secrets,” Bitfirell said. “From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets.”

The platform believes that the attackers may have gotten their hands on its encryption keys, which may have led to the exposure of the names of around 1,000 users who purchased specific products that needed this information from the buyers.

“Bitrefill was designed to store very little personal data. We are a store, not a crypto service provider. We don’t require mandatory KYC. When a customer chooses to verify their account. Still, based on database logs, we know that a subset of purchase records was accessed,” it noted.

A pattern of suspicious purchases with certain suppliers was what tipped off Bitfrefill of a possible attack. Upon initial probe, the platform found that some of their web-connected hot wallets were being drained out. As of now, the platform has not disclosed exactly how much was stolen from their accounts.

Upon identifying the breach, Bitfirell said, it took its system offline. The company said the attackers possibly scanned its systems to see what could be stolen, including its crypto gift card inventory.

A thorough investigation including law enforcement agencies and on-chain analytics platforms is underway in the incident.

Crypto gift card player Bitrefill reports massive data breach, accuses Lazarus Group

Source: X/ @bitrefill

The company believes its customers do not have to take any specific action in the situation for now.

“Almost everything is back to normal: payments, stock, accounts. Sales volumes are also back to normal, and we are eternally thankful to our customers for your continued confidence in us,” the company vouched.

Old and new customers who may have engaged with the Bitrefill website have, however, been cautioned against unexpected communications related to Bitrefill or crypto.

Coin Headlines covers the latest news in crypto, blockchain, Web3, and markets, bringing you credible and up-to-date information on all the latest developments from around the world.

We focus on real-time news updates, market movements, whale transfers, and macroeconomic trends to keep you informed and engaged. Whether it’s Bitcoin price swings, altcoin updates, meme coin hype, regulatory changes, or major moves from the world of traditional finance, Coin Headlines gives you what you need to know, right when you need it.