THURSDAY, MAR19
1. Bitrefill Lazarus attack, 2. Taxed out, 3. Nostr silent payments, 4. Invisible AI attacks
From Proto and Bitkey - part of the Bitcoin ecosystem at Block, Inc.
1. lazarus
Bitcoin e-commerce platform Bitrefill disclosed a cyberattack that originated when attackers compromised an employee laptop and extracted legacy credentials tied to production systems. According to Micah Zimmerman, the breach allowed threat actors to escalate access across Bitrefill's infrastructure, drain an undisclosed amount from cryptocurrency hot wallets, and exploit gift card inventory systems to place fraudulent vendor purchases. Approximately 18,500 purchase records were accessed, with around 1,000 involving encrypted customer names now treated as potentially exposed. Bitrefill said it will absorb the financial losses through operational capital and has since restored normal service levels. The company attributed the attack to North Korea's Lazarus Group based on malware similarities, reused IP infrastructure, and on-chain transaction patterns consistent with Bluenoroff, the group's financially focused subunit. "Based on our investigation and logs, we don't have reason to think that customer data was the objective," Bitrefill noted, pointing instead to cryptocurrency holdings and gift card inventory as the apparent targets. Blockchain analytics firm Chainalysis estimates North Korea-linked groups stole over $2 billion in digital assets in 2025 alone, making state-sponsored intrusion a recurring operational risk for any company holding liquid bitcoin balances.
-EDITOR·OP_DAILY2. taxed
Bitcoin miner HIVE Digital has announced it will cease bitcoin mining operations at its Boden, Sweden facility, citing tax-related financial strain that has rendered the site economically unviable. According to Blockspace Media, the closure reflects the compounding effect of Sweden's energy taxation on mining margins, a pressure that has been building since European energy policy tightened following the 2022 energy crisis. HIVE is simultaneously expanding its AI data center footprint in Canada, a strategic reallocation that mirrors the broader industry pivot away from high-cost jurisdictions toward infrastructure plays with diversified revenue. The Boden facility closure is a concrete data point in the ongoing reconfiguration of global hashrate distribution, as regulatory and fiscal environments in Europe continue to push energy-intensive compute toward North America and the Middle East. For miners evaluating jurisdiction risk, Sweden's experience reinforces the cost of operating in markets without stable, predictable energy taxation frameworks.
-EDITOR·OP_DAILY3. nostr
A new implementation proposal on Delving Bitcoin outlines a system for receiving Silent Payments without requiring blockchain scanning, using Nostr's encrypted messaging layer as the notification transport. Developer setavenger and BIP-352 co-author RubenSomsen have been collaborating on the design since January, with a working proof-of-concept built directly into Sparrow Wallet. According to the Sparrow fork's documentation, the system uses NIP-17 encrypted direct messages to deliver UTXO claim data automatically when bitcoin is sent to a Nostr identity, eliminating the computationally expensive tweak-scanning step that has been the primary barrier to Silent Payments adoption on resource-constrained devices. The thread has drawn scrutiny as well as interest: setavenger flagged that the current write-up "only covers the happy case," noting an absence of DoS mitigations or chain-validation checks on the notification data. That gap matters because unvalidated off-chain notifications could mislead wallets into false positives. If the trust and validation questions are resolved, Nostr-backed notifications could make privacy-preserving, reusable payment addresses practical for mobile and lightweight wallets at scale.
-EDITOR·OP_DAILY4. invisible
A threat actor tracked as Glassworm has compromised at least 151 GitHub repositories, two npm packages, and one VS Code extension using invisible Unicode characters to hide malicious payloads, with Aikido Security researchers reporting uncovering campaign. The technique exploits Private Use Area Unicode characters in ranges U+FE00 through U+FE0F, which render as zero-width whitespace in every major code editor and terminal, making the payload undetectable during visual review. At runtime, a small JavaScript decoder extracts the hidden bytes and passes them to eval(), deploying a second-stage script that steals tokens, credentials, and secrets. "The backtick string passed to s() appears to be empty in every viewer, but it's filled with invisible characters that, once decoded, produce a full malicious payload," Aikido explained. What distinguishes this wave from earlier Glassworm activity is the scale: researchers assess the attackers are using large language models to generate convincing cover commits, including version bumps and documentation tweaks, across 150-plus distinct codebases. The campaign has expanded to npm and the VS Code marketplace, consistent with Glassworm's documented pattern of pivoting between registries. Standard linting and code review offer no defense against characters that cannot be seen.
-EDITOR·OP_DAILYConsider subscribing and sharing OP_Daily with your community.

