Scammers are using lookalike Bitrefill domains that appear in search results to trick people into buying gift cards or top-ups. The fake sites copy Bitrefill’s branding and checkout flow, then display a QR code and crypto address so victims unknowingly pay the scammers instead of Bitrefill. Because crypto payments can’t usually be reversed, victims typically lose the funds and receive nothing.
How the attack worked
This campaign relies on search results rather than email or phone calls. Someone searching for "Bitrefill" or a "Bitrefill gift card" clicks a top result that looks legitimate but actually leads to a lookalike domain. The fake site closely copies Bitrefill's branding and checkout flow, walking the visitor through what feels like a normal gift card or top-up purchase. At the payment step, the page shows a QR code, a one-time-use crypto address, and a countdown clock giving the visitor under an hour to send funds. The only real difference from a legitimate purchase is where the money goes: instead of reaching Bitrefill, it goes directly to an address controlled by the scammers.
Why it succeeded
The operation appears built like a polished e-commerce funnel rather than a quick, one-off scam page. Key findings note the use of commercial analytics software alongside the lookalike checkout, suggesting the operators are tracking and optimizing conversion the way a legitimate retailer would. Typosquatted domains and internationalized (Punycode) addresses make the URLs look correct at a glance, and because the checkout mirrors Bitrefill's real flow so closely, there is little in the visual experience itself to signal a problem. The countdown timer and preset payment amounts add urgency that discourages a careful second look.
What to watch for
- Domains that are not exactly bitrefill.com, including versions with an added word like "pay" or "gift"
- Internationalized or Punycode domains (rendered as xn-- in the browser) that visually mimic the real brand
- Being handed from the domain you started on to a different checkout domain
- A countdown timer pressuring immediate payment
- Inconsistent currency symbols during amount selection
How to build resistance
Treat search results for payment and checkout pages as untrusted, even when they rank near the top. The safest approach is to use a saved bookmark or type the address directly rather than clicking through search listings. Before approving any payment, confirm that the domain is exactly the one the company uses, since seeing the right brand name somewhere in the URL is not enough to confirm legitimacy. Because cryptocurrency payments generally cannot be reversed, this verification needs to happen before funds are sent, not after. Anyone who buys gift cards, eSIMs, or digital goods on behalf of their organization, including finance and procurement staff, should build this domain check into routine purchasing habits. Finally, be cautious of any follow-up offer promising to recover lost cryptocurrency for an upfront fee, since these recovery services are often a second scam layered on top of the first.
Key findings
- Victims are funneled from search results to lookalike domains impersonating Bitrefill.
- The fake sites closely copy Bitrefill’s branding and checkout flow to make crypto payment requests look normal.
- Victims are given a QR code and payment address that routes funds directly to scammers, with little chance of recovery.
- The campaign appears optimized like an e-commerce funnel (including commercial analytics software) rather than a one-off scam.
- Attackers use typosquatting and internationalized domains (Punycode/xn--) to make URLs look legitimate at a glance.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Procurement, Anyone who buys gift cards, eSIMs, or digital goods for work.
- Affected industries: E-commerce / online retail, Consumer services, Gift cards and digital goods.
- Attack channels: website.
- Impersonated: Bitrefill.
Red flags to watch for
- Domain is not exactly bitrefill.com (extra words like “pay”/“gift” or subtle letter swaps)
- Internationalized/Punycode domains that visually mimic the real brand
- Checkout domain differs from where the user started (being handed to a second related domain)
- Countdown timer pressure to pay quickly
- Inconsistent currency symbols during amount selection
- Crypto address is not verifiably associated with Bitrefill and the domain is not bitrefill.com
Frequently asked questions
How do fake Bitrefill sites appear in search results?
Scammers register lookalike domains, sometimes using typosquatting or internationalized Punycode addresses, that appear in search results and closely copy Bitrefill's branding and checkout flow.
How do victims lose money in this scam?
Victims complete what looks like a normal purchase, but instead of paying Bitrefill they send cryptocurrency to a QR code and address controlled by scammers, with little chance of recovery.
Can I get my money back after sending crypto to the wrong address?
Cryptocurrency payments generally cannot be reversed or charged back, so recovery is unlikely once funds are sent to the scammer's address.
What are the red flags of this type of scam?
Watch for domains that are not exactly bitrefill.com, extra words like pay or gift added to the brand name, internationalized domains that resemble the real one, and countdown timers pressuring quick payment.
Read the video transcript
You Google “Bitrefill gift card,” click the top result, and the site looks exactly like Bitrefill… but it isn’t. These fake Bitrefill sites copy the logo, colors, and checkout flow. You pick an amount, enter your email, and it all feels normal, until you hit a payment screen that’s actually wired to the scammers. The aha: the only real difference is the crypto address. The fake Bitrefill checkout shows a QR code, a one-time-use address, and a countdown clock, once you send, that crypto goes straight to them, and you’re not getting it back. Before you send any crypto, stop and read the address bar. Type bitrefill.com yourself or use a bookmark, never trust a checkout you reached from a search result alone.