Thomas

1.9K posts

Thomas banner
Thomas

Thomas

@thomasbtc

Head of Customer Happiness @bitrefill | Helping everyone live on crypto | Love wine, Warriors, Niners, and Giants | De gustibus non est disputandum

Katılım Kasım 2012
2.2K Takip Edilen658 Takipçiler
Sabitlenmiş Tweet
Thomas
Thomas@thomasbtc·
So good, it sounds like a scam...Bitrefill.
Rodde@live_0n_crypt0

Shoutout to @jasontheween for the mention on @TheICHpodcast! 🙌 For anyone wondering, @bitrefill has been around since 2014, helping people spend crypto on everyday things like gift cards, phone top-ups, eSims and more across 170+ countries. 11 years of making it easy to live on crypto. Would love to come the show and break it all down 👀. DMs are open! ⚡

English
1
0
6
768
Thomas retweetledi
Liquity
Liquity@LiquityProtocol·
BOLD can never be frozen or stopped that's it, that's the tweet hold decentralized stablecoins.
ZachXBT@zachxbt

@circle @FastCompany How come Circle froze the USDC balance of 16 unrelated hot wallets late yesterday for a civil case? A basic review of onchain activity makes it obvious they are operational wallets. You fail to protect users during actual incidents yet respond to a request riddled with errors…

English
9
7
254
3K
Thomas
Thomas@thomasbtc·
It was awesome chatting with @Crypto_Goblinz at @EthereumDenver
WeavingWeb3@WeavingWeb3

Today @Crypto_Goblinz is sitting down with @thomasbtc from @bitrefill We talk about why spending crypto should go straight from your wallet to the merchant with no middlemen, how gift cards create a privacy layer that debit cards can’t, why current infrastructure isn’t built for AI agents but Bitrefill’s rails are, and their vision for paying your mortgage, insurance, and tuition directly from your Metamask. jump to what excites you below: 0:00 - Intro & what is Bitrefill? Spending crypto directly from your wallet since 2014 0:46 - How it works: wallet → Bitrefill → gift card in 7 seconds (Uber, Airbnb, DoorDash) 1:28 - The privacy problem with crypto debit cards (Visa, MasterCard & your data) 2:24 - Privacy adoption: privacy pools, Fluidkey stealth addresses & what’s coming 3:43 - How Bitrefill keeps it permissionless — like buying a gift card with cash at CVS 4:50 - What’s next: US bill pay is coming back — pay your mortgage from your wallet 6:07 - Bitrefill isn’t just gift cards — it’s real-world crypto empowerment 6:41 - AI agent payments: the talk of the town & why gift card rails are the perfect fit 7:46 - Imagine your AI agent booking Hawaii, buying cabinets at Lowe’s — all permissionless 9:37 - Bitrefill is hiring! Web3 devs, PMs & agent payment builders (100% remote since before COVID) 10:34 - Advice: just try stuff — keeping an open mind led Thomas deep into DeFi

English
2
0
2
47
Ari Eiberman 🇦🇷 Stablecards
I’m a bit embarrassed to ask this, but… Where can I take out a loan using self-custodied Bitcoin as collateral? With a low APY, obviously. And preferably no wBTC or similar wrappers 🙏
English
147
4
123
38.7K
Thomas retweetledi
Nerite
Nerite@NeriteOrg·
Check out our new trove explorer and see every open position on Nerite. See how people are borrowing millions against their tBTC, rETH, ARB, and more.
Nerite tweet media
English
2
3
16
981
Thomas retweetledi
Mitch Goldich 🐙
Mitch Goldich 🐙@mitchgoldich·
The biggest game of the first round is on Friday, when Long Island battles Arizona for iced tea supremacy
Mitch Goldich 🐙 tweet media
English
422
10.3K
92.2K
5.4M
Thomas
Thomas@thomasbtc·
@TallNupinks @bitrefill It is could be related to some of the security measures taken. Logging out and back in general does work. If you aren’t receiving the 2FA emails, be sure to note that in your ticket because that is also a related issue.
English
1
0
1
63
Tall Nupinks
Tall Nupinks@TallNupinks·
@bitrefill Interesting timing. I've been trying to access my account, and 2FA emails are not arriving. Your support simply tell me to "clear my cache"🙄. Can anyone please help, @bitrefill ??
English
3
0
0
889
Bitrefill
Bitrefill@bitrefill·
March 1st incident report On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation - including the modus operandi, the malware used, on-chain tracing and reused IP + email addresses (!) - we find many similarities between this attack and past cyberattacks by the DPRK Lazarus / Bluenoroff group against other companies in the crypto industries. The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated. That credential provided access to a snapshot containing production secrets. From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets. We first detected the incident after noticing suspicious purchasing patterns with certain suppliers. We realized that our gift card stock and supply lines were being exploited. At the same time we found some of our hot wallets being drained and funds transferred to attacker-controlled wallets. The moment we identified the breach, we took all of our systems offline as part of our containment response. Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial. Since the incident, our team has been working closely with top industry security researchers, incident response specialists, on-chain analysts and law enforcement to understand what happened and how we can prevent it from happening again. A sincere thank you to @zeroshadow_io, @SEAL_Org, @RecoverisTeam and @fearsoff for their rapid response and support throughout this ordeal. What about your data Based on our investigation and our logs we don’t have reason to think that customer data was the target of this breach. There is no evidence that they extracted our entire database, only that the attackers ran a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory. Bitrefill was designed to store very little personal data. We are a store, not a crypto service provider. We don’t require mandatory KYC. When a customer chooses to verify their account - e.g. to access higher purchasing tiers or certain products - that data is kept exclusively with our external KYC provider, with no backups in our system. Still, based on database logs, we know that a subset of purchase records was accessed and we want to be transparent about that. Around 18,500 purchase records were accessed by the attackers. Those records contained limited customer information, such as email addresses, crypto payment address, and metadata including IP address. For approximately 1,000 purchases, specific products required customers to provide a name. That information is encrypted in our database. However, since the attackers may have gotten access to the encryption keys, we are treating this data as potentially accessed. Customers in this category have already been notified directly by email. At this time, based on the information currently available, we do not believe customers need to take specific action. As a precaution, we recommend remaining cautious of any unexpected communications related to Bitrefill or crypto. If this assessment changes, we will of course immediately inform those affected. What we are doing We have already significantly improved our cybersecurity practices, but vow to continue to draw learnings from this experience to make sure user and company balances and data remain maximally safe. Specifically we’re: -Continuing thorough cybersecurity reviews and pentests with multiple external experts and implementing recommendations; -Further tightening internal access controls; -Further improving logging and monitoring for faster detection and more effective response; and -Continuing to refine and test our incident response procedures and automated shutdown procedures. The bottom line Getting hit by a sophisticated attack sucks (a lot). We’ve been in business for over 10 years and it’s the first time we’ve been hit this hard. But we survived. Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital. Almost everything is back to normal: payments, stock, accounts. Sales volumes are also back to normal, and we are eternally thankful to our customers for your continued confidence in us. We will continue to do our best to continue deserving your trust. Thank you!
English
114
146
983
178K
Bitrefill
Bitrefill@bitrefill·
More payment methods are back.   Binance Pay and fiat are live again. So is our @lifiprotocol integration, which you can use to shop on Bitrefill from 50+ chains with 6,000+ tokens.   Getting closer to full speed. Stay tuned: bitrefill.com/service
English
22
23
112
4.7K
Thomas
Thomas@thomasbtc·
@pet3rpan_ Best time zone to hire from. You get the most working hours from PST.
English
0
0
0
55
Peter / 1k(x)
Peter / 1k(x)@pet3rpan_·
PST is literally the worst Timezone, I can’t believe how y’all actively are able to do this consistently
English
12
1
31
3.4K
Thomas retweetledi
cinesius.eth
cinesius.eth@cinesiusss·
Never blame your user.
English
2
1
13
288
Jonathan Han
Jonathan Han@0xJHan·
Looking forward to speaking at @RWASummit in Cannes about RWA lending and distribution and how real-world assets are reshaping finance.
Jonathan Han tweet media
English
7
3
40
3.6K
CoinGecko
CoinGecko@coingecko·
Overlooked project?
English
838
56
748
78.4K