Close Menu
Emirates InsightEmirates Insight
  • The GCC
    • Duabi
  • Business & Economy
  • Startups & Leadership
  • Blockchain & Crypto
  • Eco-Impact

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

UAE Launches Phase 1 Of R&D Tax Incentives Programme

March 19, 2026

North Korea-Linked Hackers Suspected in Bitrefill Breach That Drained Wallets

March 19, 2026

Australia’s problem isn’t innovation – it’s the investment architecture for the ‘missing middle’

March 19, 2026
Facebook X (Twitter) Instagram LinkedIn
  • Home
  • Get Featured
  • Guest Writer Policy
  • Privacy Policy
  • Terms of Use
  • Contact Us
Facebook X (Twitter) Instagram LinkedIn
Emirates InsightEmirates Insight
  • The GCC
    • Duabi
  • Business & Economy
  • Startups & Leadership
  • Blockchain & Crypto
  • Eco-Impact
Emirates InsightEmirates Insight
Home»Blockchain & Crypto»North Korea-Linked Hackers Suspected in Bitrefill Breach That Drained Wallets
Blockchain & Crypto

North Korea-Linked Hackers Suspected in Bitrefill Breach That Drained Wallets

Emirates InsightBy Emirates InsightMarch 19, 2026No Comments
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Bitrefill said hackers drained hot wallets and exploited gift card supply flows after gaining access through stolen credentials from an employee’s device.

Bitrefill disclosed that it was targeted in a cyberattack on March 1, which resulted in the theft of cryptocurrency funds, and said its investigation found multiple indicators linking the incident to tactics used by the DPRK-associated Lazarus/Bluenoroff group.

The company stated that similarities in the attackers’ methods, malware, on-chain tracing patterns, and the reuse of IP and email addresses are consistent with previous operations attributed to the group.

Bitrefill Cyberattack

According to the company, the breach originated from a compromised employee’s laptop, where a legacy credential was extracted. That credential allowed access to a snapshot containing production secrets, which the attackers then used to expand their access across Bitrefill’s systems. This enabled them to reach parts of the database and certain cryptocurrency wallets.

In its latest tweet, Bitrefill said it first identified the incident after detecting unusual purchasing patterns involving some suppliers, which indicated that its gift card inventory and supply flows were being misused. At the same time, it observed that some hot wallets were being drained, and funds were sent to addresses controlled by the attackers. Once the breach was confirmed, the company shut down all systems to contain the situation.

Following the incident, Bitrefill confirmed that it has been working with external cybersecurity experts, incident response teams, blockchain analysts, and law enforcement.

The company said there is no indication that customer data was the main focus of the attack. According to its logs, the attackers ran a limited number of database queries consistent with probing activity to identify what could be extracted. This included cryptocurrency and gift card inventory. Bitrefill added that it stores minimal personal data and does not require mandatory KYC, with any verification information held by an external provider.

However, it confirmed that about 18,500 purchase records were accessed, including email addresses, cryptocurrency payment addresses, and metadata such as IP addresses. In roughly 1,000 cases where customers had provided names for specific products, the information was encrypted, but the company is treating it as potentially accessed due to possible exposure of encryption keys. Those users have been notified.

You may also like:

Bitrefill said it does not currently believe customers need to take specific action, but advised vigilance regarding any unexpected communications related to Bitrefill or cryptocurrency.

The company added that it has strengthened its security measures, including conducting further external cybersecurity reviews and penetration testing, tightening internal access controls, improving monitoring and logging systems, and refining incident response procedures. It said the financial losses will be covered from its operational capital, and that most services, including payments and inventory, have been restored.

Lazarus Havoc

Even as many crypto platforms have ramped up their security frameworks in recent years, threat actors continue to bypass protections. The Lazarus Group remains the sector’s most persistent and dangerous adversary, responsible for the largest crypto hack on record after stealing $1.4 billion from Bybit in February 2025.

Blockchain investigator ZachXBT previously said that breaches involving platforms such as Bybit, DMM Bitcoin, and WazirX saw stolen funds laundered with ease. The on-chain investigator had added that the laundering groups have “seemingly won the battle” over enforcement.

SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Courtesy: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Emirates Insight
  • Website

Related Posts

Trending New Crypto GCOIN by PlayNance Debuts With 14 Billion Tokens Sold Already

March 18, 2026

Bitcoin ETF Holders Are $5K Underwater Even as Institutional Demand Returns

March 18, 2026

What’s Next for XRP After Reclaiming Key Resistance?

March 17, 2026
Leave A Reply Cancel Reply

Emirates Insight
LIMITED FEATURE SPOTS
Get Featured. Get Seen.
Position your brand in front of founders, decision makers and professionals across the UAE.
APPLY TO GET FEATURED
Top Posts

Global Leaders Unite at World Climate Summit, The Investment COP 2023 to Redefine Climate Action

December 11, 20235,009 Views
AI & Innovation 2 Mins ReadSponsor: Doers Summit

Doers Summit 2025 opens in Dubai with strong Global participation

Sponsor: Doers Summit November 26, 2025

Australia Risks Falling Behind in Climate Investment, New Report Warns

August 21, 20253,049 Views

How to Start and Scale an E-Commerce Business in the UAE

May 15, 20253,016 Views
Emirares Insight

Emirates Insight - Lens on the Gulf provides in-depth analysis of the Gulf's business landscape, entrepreneurship stories, economic trends, and technological advancements, offering keen insights into regional developments and global implications.

We're accepting always open for new ideas and partnerships.

Email Us:[email protected]

Facebook X (Twitter)
Our Picks

UAE Launches Phase 1 Of R&D Tax Incentives Programme

March 19, 2026

North Korea-Linked Hackers Suspected in Bitrefill Breach That Drained Wallets

March 19, 2026

Australia’s problem isn’t innovation – it’s the investment architecture for the ‘missing middle’

March 19, 2026
© 2020 - 2026 Emirates Insight. | Designed by Linc Globa Hub inc.
  • Home
  • Get Featured
  • Guest Writer Policy
  • Privacy Policy
  • Terms of Use
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.