Bitcoin payment service provider Bitrefill announced on the X platform that it experienced a cyberattack on March 1, 2026, leading to a customer data breach. According to Odaily, the attack originated from a compromised employee laptop, allowing attackers to access parts of the database and cryptocurrency wallets. The investigation revealed that the attack methods closely resemble those used by the North Korean DPRK Lazarus/Bluenoroff hacking group in previous attacks on crypto companies. Approximately 18,500 purchase records involving limited customer information, such as email addresses, crypto payment addresses, and IP metadata, were affected. Around 1,000 records contained encrypted customer names, which may have been accessed.
Bitrefill stated that customers do not need to take any specific actions but advised them to remain vigilant for unusual information. The company has isolated the affected systems and is collaborating with security experts, on-chain analysts, and law enforcement agencies. Operations have nearly returned to normal. Bitrefill emphasized its long-term profitability and sufficient funds to absorb the loss, and it plans to continue strengthening cybersecurity measures, including internal access controls, monitoring, and emergency response mechanisms.