Crypto Retailer Bitrefill Says Lazarus Group Hack Led to Stolen Funds
Bitrefill is a gift-card and e-commerce platform that accepts cryptocurrency payments and relies on hot wallets for instant transfers in its daily operations. The incident is suspected of involving North Korean hacking group Lazarus Group. Beyond the asset losses, it highlights how employee devices, old credentials and snapshots containing sensitive data can become cybersecurity weak points in the supply chain.
Bitrefill recently disclosed that its platform was breached on March 1. The attacker is suspected of installing malware on an employee’s laptop and using old credentials and snapshots of secrets to gain system access, steal funds from hot wallets and access about 18,500 purchase records. The company has not disclosed the amount stolen but said it would absorb all losses.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.