Summary
- Crypto asset payments platform Bitrefill said funds from its hot wallet were leaked in a hacking attack.
- Bitrefill said it will fully cover the loss of stolen funds with operating funds, and that services and sales volumes have recovered.
- Bitrefill said it is cooperating with law enforcement agencies and security firms and has strengthened internal access controls and its monitoring system.
Forecast Trend Report by Period



Crypto asset payments platform Bitrefill was hit by a hacking attack that resulted in funds being stolen, and indications of involvement by North Korea’s Lazarus Group have been identified.
According to Cointelegraph on the 17th (local time), Bitrefill said it suffered a cyberattack on March 1 in which an employee laptop was infected with malware, leading to an outflow of funds from its hot wallet.
Bitrefill explained that “the attacker compromised employee devices using malware, on-chain tracking, and reused IP and email infrastructure.”
The attack also enabled access to roughly 18,500 purchase records, raising the possibility that some customer information was exposed. The company emphasized, however, that there were no confirmed signs that the entire database was leaked.
Bitrefill said, “The attacker appears to have conducted limited queries to determine what assets could be stolen, rather than extracting the entire database.”
North Korean hacking group BlueNoroff, which is linked to the Lazarus Group, was also cited as being behind the attack. Bitrefill said the group may have carried out the attack alone or in collaboration.
The amount of funds stolen was not disclosed, but the company said it “will fully cover the loss with operating funds.”
Bitrefill said services have now returned to normal. The company stated, “Most functions—payments, inventory, accounts, and more—are back to normal, and sales volumes have recovered,” adding that it is “grateful for customers’ trust.”
Following the incident, Bitrefill said it has worked with law enforcement agencies and security firms in its response, and has significantly strengthened security measures, including tighter internal access controls and improved monitoring systems.

YM Lee
20min@bloomingbit.ioCrypto Chatterbox_ tlg@Bloomingbit_YMLEE




![Stocks Close Higher Despite a Rebound in Oil…Micron Up 4.5% [New York Market Briefing]](https://media.bloomingbit.io/PROD/news/eb5d383a-a255-4dc2-9060-f443903fb850.webp?w=250)
