Data Breaches · Financial Fraud

Lazarus-linked Hack Drains Bitrefill Wallets, Exposes 18,500 Records

North Korea–linked Lazarus Group compromised a Bitrefill employee laptop and drained funds from the company's hot wallets. Attackers exfiltrated about 18,500 purchase records containing email addresses, crypto payment addresses and IP metadata. Bitrefill says there is no evidence of a full database extraction, has largely restored services, and will absorb losses from operational capital.

2 sources · Mar 20

Timeline

Sources

Part of the PlainSec briefing for 2026-03-18

Every edition of this story: Lazarus-linked Hack Drains Bitrefill Wallets, Exposes 18,500 Records