Crypto e-commerce platform Bitrefill accuses North Korea of stealing 18,500 purchase records
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解主要信息。文章讲的是朝鲜黑客攻击了Bitrefill平台,窃取了用户数据和加密货币。攻击发生在3月1日,黑客来自 Lazarus 组织,他们通过入侵员工电脑获取了凭证,进而访问了数据库和钱包。损失情况没有详细说明,但提到了Bitrefill计划用运营资金弥补。 接下来,我需要确定关键点:攻击者是谁(朝鲜 Lazarus 组织)、攻击时间(3月1日)、受影响的平台(Bitrefill)、窃取的数据类型、以及损失情况。还要注意文章提到的其他事件,比如Lazarus之前偷过钱,但这些可能不需要在总结中详细说明。 然后,我要把这些信息浓缩到100字以内。确保语言简洁明了,直接描述事件。不需要复杂的句子结构或专业术语,让读者一目了然。 最后检查一下字数是否符合要求,并确保所有关键信息都被涵盖。这样用户就能快速了解文章的主要内容了。 </think> 朝鲜黑客通过入侵员工电脑获取凭证后攻击加密货币平台Bitrefill,窃取用户数据及资金。 2026-3-18 02:1:5 Author: therecord.media(查看原文) 阅读量:3 收藏

North Korean hackers targeted cryptocurrency e-commerce platform Bitrefill during an attack on March 1, according to a post-mortem from the company published Tuesday. 

In a lengthy statement, Bitrefill said hackers allegedly tied to North Korea’s Lazarus group accessed around 18,500 purchase records that contained email addresses, crypto payment addresses and metadata including IP addresses.

Bitrefill is designed to allow people to live off of cryptocurrency, enabling users to buy digital gift cards or pay bills online with it. The company has partnerships with Amazon, Doordash, Apple, Uber, Walmart and more.

The company first announced issues on March 1 and eventually was forced to take systems offline when it was discovered to be a security breach. 

The company restored its website and app on March 5, intimating at the time that North Korea was responsible for the attack. Law enforcement and cybersecurity experts assisted in the investigation. 

In its post-mortem, the company confirmed that based on the tactics, malware, IP addresses, email addresses and blockchain activity, the incident was attributed to hackers connected to North Korea's Lazarus Group. 

“The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated,” the company said. “That credential provided access to a snapshot containing production secrets. From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets.”

The breach was discovered because they noticed suspicious purchasing patterns with certain suppliers — tipping off that their gift card stock and supply lines were being exploited.

Some company cryptocurrency wallets were drained and funds were transferred to hacker-controlled wallets. 

The statement does not say how much was taken and whether those funds were clawed back. Bitrefill did not respond to requests for comment. The company said it plans to absorb the losses through its operational capital.

Bitrefill claims the hackers were not after their entire customer database and conducted “a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory.”

In November, the Justice Department said it was able to seize more than $15 million that had been stolen by Lazarus during four separate incidents in 2023. 

Lazarus is allegedly organized within the North Korean Reconnaissance General Bureau and has stolen billions worth of cryptocurrency over the last nine years, with blockchain monitoring firm Chainalysis saying hacking groups connected to North Korea’s government stole $1.3 billion worth of cryptocurrency across 47 incidents in 2024.

Chainalysis reported that more than $2 billion worth of crypto was taken by North Korean hackers last year. Much of the figure is attributed to the $1.5 billion theft from Dubai-based platform Bybit in February, South Korean officials also accused North Korea of stealing $30 million worth of cryptocurrency from crypto platform Upbit. 

As seen in the attack on Bitrefill, North Korean actors have typically focused on stealing private keys or secrets that grant a person full control over digital assets. 

Since Chainalysis began tracking the figures in 2022, North Korea has stolen $6.8 billion in crypto. The United Nations said in 2024 that it is tracking dozens of incidents over a five-year period that have netted North Korea about $3 billion.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/crypto-platform-accuses-north-korea-hack
如有侵权请联系:admin#unsafe.sh