Bitrefill

13K posts

Bitrefill banner
Bitrefill

Bitrefill

@bitrefill

Shop with internet money at the best brands, pay bills & refill phones worldwide 🌎🌍🌏 Earning ₿itcoin back as you go.

参加日 Ekim 2014
5.5K フォロー中73.6K フォロワー
固定されたツイート
Bitrefill
Bitrefill@bitrefill·
ZXX
12
11
75
7.1K
Bitrefill がリツイート
Bitrefill
Bitrefill@bitrefill·
ZXX
12
11
75
7.1K
Julian Figueroa
Julian Figueroa@kinetic_finance·
if you didn't know, a Bitcoin company actually has one of the BEST phone data plans. Bitrefill has eSims for 10-40% cheaper than other eSim providers, AND you get 5% in Bitcoin back on every purchase. I have ~43 more FREE 1GB of eSims to giveaway too, go grab one! 👇
Julian Figueroa tweet media
English
8
3
25
2.7K
Bitrefill
Bitrefill@bitrefill·
March 1st incident report On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation - including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) - we find many similarities between this attack and past cyberattacks by the DPRK Lazarus / Bluenoroff group against other companies in the crypto industries. The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated. That credential provided access to a snapshot containing production secrets. From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets. We first detected the incident after noticing suspicious purchasing patterns with certain suppliers. We realized that our gift card stock and supply lines were being exploited. At the same time we found some of our hot wallets being drained and funds transferred to attacker-controlled wallets. The moment we identified the breach, we took all of our systems offline as part of our containment response. Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial. Since the incident, our team has been working closely with top industry security researchers, incident response specialists, on-chain analysts and law enforcement to understand what happened and how we can prevent it from happening again. A sincere thank you to @zeroshadow_io, @SEAL_Org, @RecoverisTeam and @fearsoff for their rapid response and support throughout this ordeal. What about your data Based on our investigation and our logs we don’t have reason to think that customer data was the target of this breach. There is no evidence that they extracted our entire database, only that the attackers ran a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory. Bitrefill was designed to store very little personal data. We are a store, not a crypto service provider. We don’t require mandatory KYC. When a customer chooses to verify their account - e.g. to access higher purchasing tiers or certain products - that data is kept exclusively with our external KYC provider, with no backups in our system. Still, based on database logs, we know that a subset of purchase records was accessed and we want to be transparent about that. Around 18,500 purchase records were accessed by the attackers. Those records contained limited customer information, such as email addresses, crypto payment address, and metadata including IP address. For approximately 1,000 purchases, specific products required customers to provide a name. That information is encrypted in our database. However, since the attackers may have gotten access to the encryption keys, we are treating this data as potentially accessed. Customers in this category have already been notified directly by email. At this time, based on the information currently available, we do not believe customers need to take specific action. As a precaution, we recommend remaining cautious of any unexpected communications related to Bitrefill or crypto. If this assessment changes, we will of course immediately inform those affected. What we are doing We have already significantly improved our cybersecurity practices, but vow to continue to draw learnings from this experience to make sure user and company balances and data remain maximally safe. Specifically we’re: -Continuing thorough cybersecurity reviews and pentests with multiple external experts and implementing recommendations; -Further tightening internal access controls; -Further improving logging and monitoring for faster detection and more effective response; and -Continuing to refine and test our incident response procedures and automated shutdown procedures. The bottom line Getting hit by a sophisticated attack sucks (a lot). We’ve been in business for over 10 years and it’s the first time we’ve been hit this hard. But we survived. Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital. Almost everything is back to normal: payments, stock, accounts. Sales volumes are also back to normal, and we are eternally thankful to our customers for your continued confidence in us. We will continue to do our best to continue deserving your trust. Thank you!
English
111
140
960
162.7K
🫡Pingu
🫡Pingu@web3pingu·
@bitrefill Thankyou for being so transparent through it all Best in class Comms
English
2
0
53
5.3K
Bitrefill
Bitrefill@bitrefill·
More payment methods are back.   Binance Pay and fiat are live again. So is our @lifiprotocol integration, which you can use to shop on Bitrefill from 50+ chains with 6,000+ tokens.   Getting closer to full speed. Stay tuned: bitrefill.com/service
English
22
19
105
4.4K
Bitrefill
Bitrefill@bitrefill·
@Edu7ab Please check again, it's live now🫡
English
1
0
1
68
Liquidity Dude
Liquidity Dude@Edu7ab·
@bitrefill Hi, what happened to the Binance Pay payment option? I can't see it anymore
English
1
0
0
89
Bitrefill
Bitrefill@bitrefill·
A big part of our payment methods are back up and running. Live now: Bitcoin, Lightning, Litecoin, Ethereum, EVMs, and Solana. Everything else is coming back during the next week. You can track real-time updates here: bitrefill.com/service
English
54
55
242
13.5K
Bitrefill
Bitrefill@bitrefill·
@MaxLonged @trondao @litecoin Hi, we had a temporary outage on some products earlier today. Please send us a DM with your order info and we will get this handled for you!
English
0
0
1
97
Bitrefill
Bitrefill@bitrefill·
Payment rails restored 🟢 →USDT is available on the @trondao network. →@litecoin is back. →Our integration widget is back too. Shop from your favorite wallet or exchange just like before. Remaining methods will be restored soon. Real-time updates: bitrefill.com/service
English
20
35
128
4.4K
Bitrefill
Bitrefill@bitrefill·
@Ricky20986644 We are sorry about the issues you are experiencing. Please share your ticket ID here or in DMs so we can look into it or open one if you haven't yet: help.bitrefill.com
English
3
0
0
270
Ricky
Ricky@Ricky20986644·
@bitrefill Don’t trust it. Some gift cards won’t work online when they used to before the “system crash” and they WILL NOT refund you if that happens. They’re scamming.
English
1
0
0
289
Bitrefill
Bitrefill@bitrefill·
Bitrefill Lightning addresses are live again. → Top up your store credit easily and instantly. → Send to friends & family for gifting and shopping needs. → Share yours to others. Drop your @ bitrefill. me address below and we’ll send you some bitcoin ⚡
English
766
138
452
13.7K
Bitrefill
Bitrefill@bitrefill·
@Oso75592541 With most vouchers this is not a problem. Which one in particular are you referring to?
English
1
0
2
614
OsoMan
OsoMan@Oso75592541·
@bitrefill How do u refund left over change on vouchers. They can't be used
English
1
0
0
694