Crypto payments platform Bitrefill suffered a cyberattack on March 1, 2026, compromising 18,500 customer order records. The attackers gained access to email addressesCrypto payments platform Bitrefill suffered a cyberattack on March 1, 2026, compromising 18,500 customer order records. The attackers gained access to email addresses

Bitrefill Breach Leads to Data Exposure and Fund Transfers

2026/03/18 17:19
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Crypto payments platform Bitrefill suffered a cyberattack on March 1, 2026, compromising 18,500 customer order records. The attackers gained access to email addresses and crypto wallet information by exploiting a compromised employee device and leaked credentials. Some funds were transferred from Bitrefill’s hot wallets, though the company has not revealed the exact amount. The breach forced the platform to take parts of its systems offline and warn users to monitor for suspicious activity.

Bitrefill Confirms Hot Wallet Breach

Bitrefill stated that attackers used a single employee laptop to access internal systems. The attackers took control of parts of the database and moved funds from hot wallets. Bitrefill acted quickly, isolating affected systems and notifying users to check for phishing or unauthorized transactions. By taking rapid action, the company limited further exposure and began investigating the full scope of the incident.

This event demonstrates the risks of connecting wallets directly to online systems. Hot wallets allow fast transactions but remain vulnerable if attackers gain access to devices or credentials. Bitrefill is reviewing its security protocols to prevent similar incidents.

Bitrefill Attack Linked to North Korea’s Lazarus Group

Cybersecurity experts and investigators linked the attack to North Korea’s Lazarus Group, also known as Bluenoroff. Analysts identified malware signatures, reused IP addresses, and blockchain traces matching previous Lazarus operations. The group previously stole $625 million from the Ronin Network in 2022 and has a history of targeting crypto platforms worldwide.

By tracking these indicators, authorities and Bitrefill can better understand how the attack occurred. This connection highlights the growing sophistication of state-backed cybercrime and the risks faced by cryptocurrency companies handling large amounts of digital assets.

Strengthening Supply Chain and Credential Security

The Bitrefill incident emphasizes the need for strong security practices. Employee devices and reused passwords remain major points of weakness. Experts recommend multi-factor authentication, strict access control, and enhanced endpoint security to reduce vulnerabilities. Bitrefill is implementing these measures while cooperating with authorities to trace stolen funds and improve internal defenses.

The company assured customers that sensitive personal information such as government IDs or passwords was not exposed. Users, however, should remain vigilant and monitor transactions closely for irregular activity.

Lessons for the Crypto Industry

This cyberattack illustrates that even established crypto platforms remain vulnerable. Companies must adopt proactive security practices, and users need to practice caution with online wallets. Bitrefill’s breach also highlights how attackers exploit human and operational weaknesses, not blockchain itself. As the crypto ecosystem grows, prioritizing security in every layer, from employee devices to wallet management, remains critical.

By learning from this event, crypto companies like Bitrefill can strengthen defenses, improve trust, and reduce the risk of future attacks. The incident underscores the importance of combining technology, policies, and user vigilance to protect digital assets.

The post Bitrefill Breach Leads to Data Exposure and Fund Transfers appeared first on Coinfomania.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

The post Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts? appeared on BitcoinEthereumNews.com. In recent crypto news, Stephen Miran swore in as the latest Federal Reserve governor on September 16, 2025, slipping into the board’s last open spot right before the Federal Open Market Committee kicks off its two-day rate discussion. Traders are betting heavily on a 25-basis-point trim, which would bring the federal funds rate down to 4.00%-4.25%, based on CME FedWatch Tool figures from September 15, 2025. Miran, who’s been Trump’s top economic advisor and a supporter of his trade ideas, joins a seven-member board where just three governors come from Democratic picks, according to the Fed’s records updated that same day. Crypto News: Miran’s Background and Quick Path to Confirmation The Senate greenlit Miran on September 15, 2025, with a tight 48-47 vote, following his nomination on September 2, 2025, as per a recent crypto news update. His stint runs only until January 31, 2026, stepping in for Adriana D. Kugler, who stepped down in August 2025 for reasons not made public. Miran earned his economics Ph.D. from Harvard and worked at the Treasury back in Trump’s first go-around. Afterward, he moved to Hudson Bay Capital Management as an economist, then looped back to the White House in December 2024 to head the Council of Economic Advisers. There, he helped craft Trump’s “reciprocal tariffs” approach, aimed at fixing trade gaps with China and the EU. He wouldn’t quit his White House gig, which irked Senator Elizabeth Warren at the September 7, 2025, confirmation hearings. That limited time frame means Miran gets to cast a vote straight away at the FOMC session starting September 16, 2025. The full board now features Chair Jerome H. Powell (Trump pick, term ends 2026), Vice Chair Philip N. Jefferson (Biden, to 2036), and folks like Lisa D. Cook (Biden, to 2028) and Michael S. Barr…
Share
BitcoinEthereumNews2025/09/18 03:14
CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
T7X Launches Regulated Launchpad for Tokenized Real-World Asset Securities

T7X Launches Regulated Launchpad for Tokenized Real-World Asset Securities

SHERIDAN, Wyo., March  18, 2026  (GLOBE NEWSWIRE) -- T7X announces the launch of the T7X Launchpad, a digital issuance platform designed to support the crea
Share
CryptoReporter2026/03/18 20:49