{"investigation":{"slug":"bitrefill","entity_name":"Bitrefill","trust_score":52,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"draft","content_type":"investigation","summary":"Bitrefill is a Stockholm-headquartered crypto e-commerce platform founded in 2014 that allows users to purchase gift cards, eSIMs, and phone top-ups with Bitcoin and other cryptocurrencies. On March 1, 2026, the company suffered a confirmed cyberattack in which attackers compromised an employee laptop, escalated access to production infrastructure and hot wallets, drained an undisclosed amount of cryptocurrency, and exfiltrated approximately 18,500 purchase records. Bitrefill publicly attributed the attack to North Korea's Lazarus Group (Bluenoroff subgroup) based on malware signatures, on-chain tracing, and reuse of IP and email addresses consistent with prior DPRK-linked operations.","sections":[{"content":"Bitrefill is a Swedish crypto e-commerce company founded in 2014 and headquartered in Stockholm, Sweden. Its founders include Sergej Kotliar, Patric Stiller, Michel Gustavsson, and Michael Grünberger. The platform enables users to spend cryptocurrency — including Bitcoin (via Lightning Network), Ethereum, Solana, USDC, USDT, Litecoin, and Dogecoin — on digital gift cards from major brands such as Amazon, Walmart, Netflix, Spotify, Apple, Airbnb, and Uber. Bitrefill also supports mobile top-ups across more than 900 phone carriers in over 170 countries. The company positions itself as a no-KYC or minimal-KYC service, which has historically attracted privacy-conscious users. Bitrefill has described itself as profitable for several years prior to the March 2026 incident.","heading":"Company Overview","sources":[{"url":"https://www.bitrefill.com/us/en/","name":"Bitrefill official website","type":"official","credibility":1},{"url":"https://coinbureau.com/review/bitrefill-review","name":"Bitrefill Review 2026 — Coin Bureau","type":"research","credibility":2},{"url":"https://www.crunchbase.com/organization/bitrefill","name":"Bitrefill — Crunchbase Company Profile","type":"other","credibility":2}],"severity":"low"},{"content":"On March 1, 2026, Bitrefill was the target of a cyberattack that resulted in the drainage of cryptocurrency from company hot wallets and the unauthorized access of approximately 18,500 customer purchase records. The company did not publicly disclose the breach until March 17–18, 2026, following a multi-week forensic investigation. Bitrefill stated that it detected the attack through suspicious purchasing patterns among suppliers and simultaneous unusual hot wallet movement. The company took all systems offline upon detection and has described operations as largely restored following a rebuilding process that took more than two weeks. No user balances or custodied funds were described as affected; Bitrefill stated that all losses were absorbed from the company's operational capital.","heading":"Incident Summary — March 1, 2026 Breach","sources":[{"url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","name":"Bitrefill blames North Korea-linked Lazarus hacker group — CoinDesk","type":"news_article","credibility":1},{"url":"https://bitcoinmagazine.com/news/bitrefill-cyberattack-points-north-korea","name":"Bitrefill Discloses Cyberattack, Points To North Korea's Lazarus Group — Bitcoin Magazine","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","name":"Bitrefill blames North Korean hackers for March 1 exploit — Cryptopolitan","type":"news_article","credibility":2},{"url":"https://x.com/bitrefill/status/2033931580352221656","name":"Bitrefill March 1st Incident Report — Official X/Twitter Post","type":"official","credibility":1}],"severity":"high"},{"content":"According to Bitrefill's public disclosure, the breach originated from a compromised employee laptop. Attackers extracted a legacy credential from that device without triggering immediate security alerts. That credential provided access to a snapshot containing production secrets. Using those production secrets, the attackers escalated privileges across Bitrefill's broader infrastructure, reaching portions of the company's database and specific cryptocurrency hot wallets. Attackers simultaneously exploited access to the gift card supply chain — triggering suspicious purchasing patterns from suppliers — while moving funds from hot wallets to attacker-controlled addresses. The exact amount of cryptocurrency drained has not been publicly disclosed. Security firms ZeroShadow, SEAL Org, and the Recoveris Team were engaged to perform blockchain tracing of stolen funds and forensic cleanup of compromised servers.","heading":"Attack Vector and Technical Details","sources":[{"url":"https://blockonomi.com/bitrefill-cyberattack-linked-to-north-koreas-lazarus-group-exposes-18500-customer-records/","name":"Bitrefill Cyberattack Linked to North Korea's Lazarus Group — Blockonomi","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","name":"Bitrefill blames North Korean hackers for March 1 exploit — Cryptopolitan","type":"news_article","credibility":2},{"url":"https://dev.to/ohmygod/hot-wallet-security-architecture-what-every-crypto-platform-must-learn-from-bitrefills-lazarus-4lop","name":"Hot Wallet Security Architecture — DEV Community analysis","type":"research","credibility":3}],"severity":"high"},{"content":"Approximately 18,500 customer purchase records were accessed during the breach. Exposed data categories include email addresses, cryptocurrency payment addresses used in prior transactions, and technical metadata including IP addresses. In approximately 1,000 of those records, encrypted names were present; Bitrefill stated that because attackers may have obtained the relevant encryption keys, these records are being treated as fully compromised. The company directly notified affected customers following the disclosure. Bitrefill emphasized that user account balances and custodied funds were not accessible to the attackers. No evidence of exposed payment card data, passwords, or KYC documentation has been reported.","heading":"Data Exposure","sources":[{"url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","name":"Bitrefill blames North Korea-linked Lazarus hacker group — CoinDesk","type":"news_article","credibility":1},{"url":"https://databreach.io/breaches/bitrefill-data-breach-linked-to-north-koreas-lazarus-group-exposes-18500-records/","name":"Bitrefill Data Breach Linked to North Korea's Lazarus Group — DataBreach.io","type":"news_article","credibility":2},{"url":"https://www.upguard.com/news/bitrefill-data-breach-2026-03-20","name":"Bitrefill Investigating Cyberattack — UpGuard","type":"research","credibility":2}],"severity":"high"},{"content":"Bitrefill attributed the March 1, 2026 attack to the North Korea-linked Lazarus Group, specifically identifying the Bluenoroff financial crime subgroup. The company stated that attribution was based on a convergence of indicators observed during the forensic investigation: (1) malware signatures consistent with tools previously attributed to Lazarus; (2) on-chain tracing of stolen funds following movement patterns characteristic of prior DPRK-linked crypto thefts; and (3) reuse of IP addresses and email addresses that had appeared in prior Lazarus Group operations targeting the cryptocurrency sector. Bitrefill described this constellation of evidence as providing strong similarity to known DPRK operations. No independent government agency has publicly confirmed this attribution as of the date of this report. The Lazarus Group / Bluenoroff subgroup has historically targeted cryptocurrency exchanges, DeFi protocols, and crypto-adjacent fintech companies; a separate 2026 report cited North Korean hackers as responsible for $577 million in crypto theft in the first four months of 2026 alone, accounting for approximately 76% of global crypto theft recorded in that period.","heading":"Lazarus Group Attribution","sources":[{"url":"https://x.com/bitrefill/status/2033931580352221656","name":"Bitrefill March 1st Incident Report — Official X/Twitter Post","type":"official","credibility":1},{"url":"https://www.scworld.com/brief/bitrefill-pins-extensive-purchase-record-exposing-hack-on-lazarus-group","name":"Bitrefill pins extensive purchase record-exposing hack on Lazarus Group — SC Media","type":"news_article","credibility":1},{"url":"https://invezz.com/news/2026/03/18/bitrefill-hack-linked-to-lazarus-what-it-reveals-about-crypto-risks/","name":"Bitrefill hack linked to Lazarus: what it reveals about crypto risks — Invezz","type":"news_article","credibility":2},{"url":"https://aiweekly.co/alerts/lazarus-group-steals-577m-via-fileless-ram-malware","name":"Lazarus Group steals $577M via fileless RAM malware — AI Weekly","type":"news_article","credibility":2},{"url":"https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus","name":"BlueNoroff Group: The Financial Cybercrime Arm of Lazarus — Picus Security","type":"research","credibility":2}],"severity":"critical"},{"content":"The precise dollar value or cryptocurrency denomination of funds drained from Bitrefill's hot wallets has not been publicly disclosed by the company or any independent security firm as of this writing. Bitrefill confirmed that hot wallets were drained and that stolen funds were transferred to addresses controlled by the attackers. The company stated that all financial losses have been absorbed from its operational capital and that it anticipates no material impact on its business continuity. Security firms ZeroShadow, SEAL Org, and Recoveris were engaged to trace stolen funds on-chain, though no public report detailing specific wallet addresses or fund flows has been released. The absence of a disclosed loss figure is consistent with Bitrefill's characterization of itself as a profitable, financially stable company with the capacity to cover losses internally.","heading":"Financial Impact and Stolen Funds","sources":[{"url":"https://cryptoimpacthub.com/north-korean-lazarus-group-hacks-bitrefill-hot-wallets-drained-customers-exposed/","name":"North Korean Lazarus Group Allegedly Hacks Bitrefill — Crypto Impact Hub","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","name":"Bitrefill blames North Korea-linked Lazarus hacker group — CoinDesk","type":"news_article","credibility":1},{"url":"https://incrypted.com/en/bitrefill-has-been-hacked-and-says-data-has-been-leaked/","name":"Bitrefill has Been Hacked and Says Data has Been Leaked — Incrypted","type":"news_article","credibility":2}],"severity":"high"},{"content":"Bitrefill detected the breach on March 1, 2026 through anomalous gift card supply chain activity and simultaneous hot wallet movement. Upon detection, the company immediately took all systems offline to prevent further damage. Infrastructure was shut down and rebuilt over a period of more than two weeks. The public disclosure was made on or around March 17–18, 2026 — approximately 17 days after the initial incident — via an official statement on X (formerly Twitter) and through outreach to affected customers. Bitrefill engaged external security specialists ZeroShadow, SEAL Org, and the Recoveris Team to conduct forensic analysis and blockchain tracing. The company also stated that it was cooperating with law enforcement agencies, though it did not specify which agencies. Bitrefill committed to absorbing all financial losses and affirmed that no user account balances were at risk.","heading":"Company Response and Disclosure","sources":[{"url":"https://x.com/bitrefill/status/2033931580352221656","name":"Bitrefill March 1st Incident Report — Official X/Twitter Post","type":"official","credibility":1},{"url":"https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","name":"Bitrefill blames North Korean hackers for March 1 exploit — Cryptopolitan","type":"news_article","credibility":2},{"url":"https://www.theblock.co/post/393974/crypto-ecommerce-bitrefill-discloses-cyberattack-north-koreas-lazarus-potential-suspect","name":"Crypto e-commerce firm Bitrefill discloses cyberattack — The Block","type":"news_article","credibility":1}],"severity":"medium"},{"content":"Bitrefill stated that it was cooperating with law enforcement as part of its incident response, but did not publicly name the agencies involved. No OFAC sanctions designation, FBI indictment, or other formal regulatory action specifically referencing the Bitrefill breach has been reported as of the time of this investigation. The Lazarus Group and its Bluenoroff subgroup are already designated entities under existing OFAC sanctions frameworks related to North Korea, and the U.S. government has previously issued public advisories regarding cryptocurrency thefts attributed to DPRK-linked actors. Whether the Bitrefill breach has been formally incorporated into any active law enforcement investigation targeting Lazarus Group infrastructure is not publicly known.","heading":"Law Enforcement and Regulatory Actions","sources":[{"url":"https://www.kucoin.com/news/flash/bitrefill-discloses-data-breach-linked-to-suspected-north-korean-hackers","name":"Bitrefill Discloses Data Breach Linked to Suspected North Korean Hackers — KuCoin News","type":"news_article","credibility":2},{"url":"https://blockonomi.com/bitrefill-cyberattack-linked-to-north-koreas-lazarus-group-exposes-18500-customer-records/","name":"Bitrefill Cyberattack Linked to North Korea's Lazarus Group — Blockonomi","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Following the breach, Bitrefill disclosed several remediation measures. The company tightened internal access controls to eliminate single-point-of-failure credential scenarios. It improved shutdown and isolation procedures to enable faster response to anomalous database queries. Comprehensive penetration testing was initiated with external security experts. Monitoring and logging capabilities were enhanced to improve threat detection speed. The company also refined incident response protocols based on lessons from the attack. Bitrefill did not disclose whether it has transitioned to cold wallet storage for a greater share of its operating funds, or what specific architectural changes were made to address the legacy credential vulnerability that served as the initial access point.","heading":"Post-Breach Security Changes","sources":[{"url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","name":"Bitrefill blames North Korea-linked Lazarus hacker group — CoinDesk","type":"news_article","credibility":1},{"url":"https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","name":"Bitrefill blames North Korean hackers for March 1 exploit — Cryptopolitan","type":"news_article","credibility":2}],"severity":"medium"},{"content":"The Bitrefill breach occurred within a broader pattern of DPRK-attributed crypto theft activity in early 2026. Reports indicate that North Korean hackers stole approximately $577 million in cryptocurrency in the first four months of 2026, accounting for an estimated 76% of all global crypto theft in that period. The Lazarus Group / Bluenoroff subgroup has historically used a range of tactics against crypto firms: spearphishing via social engineering (including fake Zoom and Microsoft Teams links), fileless malware executing entirely in RAM (such as the RemotePE trojan), and multi-stage intrusion chains beginning with credential theft and culminating in fund exfiltration. The Bitrefill breach followed a pattern consistent with these documented techniques. The BlueNoroff subgroup in particular has long focused on financial crime targets, including cryptocurrency exchanges, fintech firms, and payment processors.","heading":"Broader Context: Lazarus Group Crypto Targeting in 2026","sources":[{"url":"https://aiweekly.co/alerts/lazarus-group-steals-577m-via-fileless-ram-malware","name":"Lazarus Group steals $577M via fileless RAM malware — AI Weekly","type":"news_article","credibility":2},{"url":"https://www.infosecurity-magazine.com/news/bluenoroff-dprk-hackers-target/","name":"North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures — Infosecurity Magazine","type":"news_article","credibility":2},{"url":"https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus","name":"BlueNoroff Group: The Financial Cybercrime Arm of Lazarus — Picus Security","type":"research","credibility":2},{"url":"https://cyble.com/blog/lazarus-group-bitrefill-cyberattack/","name":"Lazarus Group Bitrefill Cyberattack Crypto Threat — Cyble","type":"research","credibility":2}],"severity":"high"}],"timeline":[{"date":"2014","event":"Bitrefill founded in Stockholm, Sweden by Sergej Kotliar, Patric Stiller, Michel Gustavsson, and Michael Grünberger.","source":"Crunchbase / Coin Bureau","source_url":"https://www.crunchbase.com/organization/bitrefill","date_original":"2014-01-01"},{"date":"2026-03","event":"Cyberattack initiated: attackers compromised an employee laptop and extracted a legacy credential, escalating access to Bitrefill's production infrastructure, databases, and hot wallets. Funds were drained and approximately 18,500 purchase records were accessed. Bitrefill detected the breach via suspicious gift card supply chain activity and anomalous wallet movement and immediately took all systems offline.","source":"Bitrefill official statement / CoinDesk","source_url":"https://x.com/bitrefill/status/2033931580352221656","date_original":"2026-03-01"},{"date":"2026-03-17","event":"Bitrefill publicly discloses the March 1 breach and attributes it to North Korea's Lazarus Group (Bluenoroff subgroup) based on malware signatures, on-chain tracing, and reused IP and email addresses consistent with prior DPRK operations.","source":"CoinDesk / Bitcoin Magazine / SC Media","source_url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records"},{"date":"2026-03-18","event":"Multiple major crypto and cybersecurity outlets report on Bitrefill's disclosure. The company confirms it is cooperating with law enforcement and that operations have largely been restored. Bitrefill commits to covering all financial losses from operational capital.","source":"Bleeping Computer / The Block / Cryptopolitan / FinanceFeeds","source_url":"https://financefeeds.com/bitrefill-says-lazarus-group-behind-march-cyberattack-compromising-18500-user-records/"}],"sources_used":[{"url":"https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","name":"Bitrefill blames North Korea-linked Lazarus hacker group — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260319142532/https://www.coindesk.com/markets/2026/03/18/bitrefill-accuses-north-korea-linked-lazarus-hacker-group-for-compromising-18-500-purchase-records","credibility":1,"archive_timestamp":"2026-03-19T14:25:32+00:00"},{"url":"https://x.com/bitrefill/status/2033931580352221656","name":"Bitrefill March 1st Incident Report — Official X/Twitter Post","type":"official","archive_url":null,"credibility":1,"archive_timestamp":null},{"url":"https://www.scworld.com/brief/bitrefill-pins-extensive-purchase-record-exposing-hack-on-lazarus-group","name":"Bitrefill pins extensive purchase record-exposing hack on Lazarus Group — SC Media","type":"news_article","archive_url":"http://web.archive.org/web/20260324033610/https://www.scworld.com/brief/bitrefill-pins-extensive-purchase-record-exposing-hack-on-lazarus-group","credibility":1,"archive_timestamp":"2026-03-24T03:36:10+00:00"},{"url":"https://bitcoinmagazine.com/news/bitrefill-cyberattack-points-north-korea","name":"Bitrefill Discloses Cyberattack, Points To North Korea's Lazarus Group — Bitcoin Magazine","type":"news_article","archive_url":"http://web.archive.org/web/20260524170647/https://bitcoinmagazine.com/news/bitrefill-cyberattack-points-north-korea","credibility":2,"archive_timestamp":"2026-05-24T17:06:47+00:00"},{"url":"https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","name":"Bitrefill blames North Korean hackers for March 1 exploit — Cryptopolitan","type":"news_article","archive_url":"http://web.archive.org/web/20260726101331/https://www.cryptopolitan.com/bitrefill-north-korean-hackers-exploit/","credibility":2,"archive_timestamp":"2026-07-26T10:13:31+00:00"},{"url":"https://blockonomi.com/bitrefill-cyberattack-linked-to-north-koreas-lazarus-group-exposes-18500-customer-records/","name":"Bitrefill Cyberattack Linked to North Korea's Lazarus Group — Blockonomi","type":"news_article","archive_url":"http://web.archive.org/web/20260809183559/https://blockonomi.com/bitrefill-cyberattack-linked-to-north-koreas-lazarus-group-exposes-18500-customer-records/","credibility":2,"archive_timestamp":"2026-08-09T18:35:59+00:00"},{"url":"https://financefeeds.com/bitrefill-says-lazarus-group-behind-march-cyberattack-compromising-18500-user-records/","name":"Bitrefill Says Lazarus Group Behind March Cyberattack — FinanceFeeds","type":"news_article","archive_url":"http://web.archive.org/web/20260319072435/https://financefeeds.com/bitrefill-says-lazarus-group-behind-march-cyberattack-compromising-18500-user-records/","credibility":2,"archive_timestamp":"2026-03-19T07:24:35+00:00"},{"url":"https://invezz.com/news/2026/03/18/bitrefill-hack-linked-to-lazarus-what-it-reveals-about-crypto-risks/","name":"Bitrefill hack linked to Lazarus: what it reveals about crypto risks — Invezz","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://databreach.io/breaches/bitrefill-data-breach-linked-to-north-koreas-lazarus-group-exposes-18500-records/","name":"Bitrefill Data Breach Linked to North Korea's Lazarus Group — DataBreach.io","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.upguard.com/news/bitrefill-data-breach-2026-03-20","name":"Bitrefill Investigating Cyberattack — UpGuard","type":"research","archive_url":"http://web.archive.org/web/20260420070455/https://www.upguard.com/news/bitrefill-data-breach-2026-03-20","credibility":2,"archive_timestamp":"2026-04-20T07:04:55+00:00"},{"url":"https://www.theblock.co/post/393974/crypto-ecommerce-bitrefill-discloses-cyberattack-north-koreas-lazarus-potential-suspect","name":"Crypto e-commerce firm Bitrefill discloses cyberattack — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260318151808/https://www.theblock.co/post/393974/crypto-ecommerce-bitrefill-discloses-cyberattack-north-koreas-lazarus-potential-suspect","credibility":1,"archive_timestamp":"2026-03-18T15:18:08+00:00"},{"url":"https://cyble.com/blog/lazarus-group-bitrefill-cyberattack/","name":"Lazarus Group Bitrefill Cyberattack Crypto Threat — Cyble","type":"research","archive_url":"http://web.archive.org/web/20260727131426/https://cyble.com/blog/lazarus-group-bitrefill-cyberattack/","credibility":2,"archive_timestamp":"2026-07-27T13:14:26+00:00"},{"url":"https://cryptoimpacthub.com/north-korean-lazarus-group-hacks-bitrefill-hot-wallets-drained-customers-exposed/","name":"North Korean Lazarus Group Allegedly Hacks Bitrefill — Crypto Impact Hub","type":"news_article","archive_url":"https://web.archive.org/web/20260811095456/https://cryptoimpacthub.com/north-korean-lazarus-group-hacks-bitrefill-hot-wallets-drained-customers-exposed/","credibility":2,"archive_timestamp":"2026-08-11T09:54:56+00:00"},{"url":"https://incrypted.com/en/bitrefill-has-been-hacked-and-says-data-has-been-leaked/","name":"Bitrefill has Been Hacked and Says Data has Been Leaked — Incrypted","type":"news_article","archive_url":"https://web.archive.org/web/20260811095408/https://incrypted.com/en/bitrefill-has-been-hacked-and-says-data-has-been-leaked/","credibility":2,"archive_timestamp":"2026-08-11T09:54:08+00:00"},{"url":"https://aiweekly.co/alerts/lazarus-group-steals-577m-via-fileless-ram-malware","name":"Lazarus Group steals $577M via fileless RAM malware — AI Weekly","type":"news_article","archive_url":"https://web.archive.org/web/20260811032113/https://aiweekly.co/alerts/lazarus-group-steals-577m-via-fileless-ram-malware","credibility":2,"archive_timestamp":"2026-08-11T03:21:13+00:00"},{"url":"https://www.infosecurity-magazine.com/news/bluenoroff-dprk-hackers-target/","name":"North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures — Infosecurity Magazine","type":"news_article","archive_url":"http://web.archive.org/web/20260622155545/https://www.infosecurity-magazine.com/news/bluenoroff-dprk-hackers-target/","credibility":2,"archive_timestamp":"2026-06-22T15:55:45+00:00"},{"url":"https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus","name":"BlueNoroff Group: The Financial Cybercrime Arm of Lazarus — Picus Security","type":"research","archive_url":"http://web.archive.org/web/20260720142524/https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus","credibility":2,"archive_timestamp":"2026-07-20T14:25:24+00:00"},{"url":"https://www.kucoin.com/news/flash/bitrefill-discloses-data-breach-linked-to-suspected-north-korean-hackers","name":"Bitrefill Discloses Data Breach Linked to Suspected North Korean Hackers — KuCoin","type":"news_article","archive_url":"http://web.archive.org/web/20260809205415/https://www.kucoin.com/news/flash/bitrefill-discloses-data-breach-linked-to-suspected-north-korean-hackers","credibility":2,"archive_timestamp":"2026-08-09T20:54:15+00:00"},{"url":"https://www.crunchbase.com/organization/bitrefill","name":"Bitrefill — Crunchbase Company Profile","type":"other","archive_url":"http://web.archive.org/web/20250504063849/https://www.crunchbase.com/organization/bitrefill","credibility":2,"archive_timestamp":"2025-05-04T06:38:49+00:00"},{"url":"https://dev.to/ohmygod/hot-wallet-security-architecture-what-every-crypto-platform-must-learn-from-bitrefills-lazarus-4lop","name":"Hot Wallet Security Architecture — DEV Community","type":"community_report","archive_url":"http://web.archive.org/web/20260320144626/https://dev.to/ohmygod/hot-wallet-security-architecture-what-every-crypto-platform-must-learn-from-bitrefills-lazarus-4lop","credibility":3,"archive_timestamp":"2026-03-20T14:46:26+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-06-04T03:35:33.340621+00:00","updated_at":"2026-08-11T21:02:19.817005+00:00"}}