Security1 publisher2 min readPublished
Fake Bitrefill checkouts collect crypto from buyers who arrive through search results
Malwarebytes found a cluster of copies of Bitrefill's checkout taking payments of up to $1,990 to addresses the operators control, with commercial analytics software installed to measure how many visitors pay.
The Watch · Security desk
What happened
- Malwarebytes examined a close copy of Bitrefill's checkout hosted on a domain built by bolting a word onto the brand name, and describes a cluster of such sites.
- The checkout offers Bitcoin, Ethereum, USDC, USDT, Solana and Litecoin, plus card payment for a small surcharge, with preset amount buttons topping out at $1,990.
- Bitrefill has said publicly that sites copying its checkout and using similar names have been turning up in search engine results, and that its security team is working with takedown specialists.
- The cryptocurrency goes to an address the scammers control, the buyer gets nothing, and Malwarebytes says recovering the payment is extremely unlikely.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A buyer reaches this by searching for a gift card brand, so the mail gateway, the MFA prompt and the issuer's fraud check are never in the transaction path at all.
- cost The whole loss lands on the buyer, because there is no card issuer to dispute with; Bitrefill's cost is impersonation of its brand and the takedown work it is paying for.
- decision Anti-phishing budget parked in email security buys nothing against this, so the money that helps goes to brand monitoring, registrar complaints and someone checking what the brand's own search results return.
- precedent A fraud page with conversion analytics on it gets tuned, so later copies of this funnel should convert better than the one Malwarebytes looked at.
The operators are counting their traffic. The fake checkout hands visitors back to a second domain in the same family, and the link it uses carries a parameter naming a search engine [8]. Malwarebytes takes that as the operators tagging arrivals by source [8]. The same page runs commercial analytics software, the kind an e-commerce team installs to see how many carts get abandoned [9]. Malwarebytes says its presence suggests the operators want to measure and improve the share of visitors who complete a payment [10]. It describes the campaigns as run as businesses, measured and tuned like any other funnel [20].
Credential phishing, as Malwarebytes lays it out, has to clear four things before the attacker sees money: steal a password, get past 2FA, log in without tripping a fraud check, and turn account access into cash [11]. Plenty of scams fall apart somewhere in there [11]. The fake checkout needs one action from the victim, which is sending the coins [12]. Three of the four points where the scheme could have broken are gone [1]. Crypto transfers generally cannot be reversed or charged back [13].
On most retail sites a demand for cryptocurrency looks wrong. Bitrefill genuinely accepts it, so on a copy of its checkout the request fits the situation [14]. The page asks for an email address for order updates and links to terms of service and a privacy policy [19]. The payment screen shows a QR code, an address marked for one-time use, the amount converted into the chosen coin, and a countdown giving just under an hour [15]. Unique addresses, expiry timers and currency conversion are all normal in real crypto checkouts, and the only meaningful difference is the address the money goes to [16]. On the site Malwarebytes examined, the visible error was inconsistent currency symbols on the amount selector [17].
Malwarebytes says the distribution does not appear to rely on email [7]. It also does not say whether the search placement was bought as advertising or earned by ranking, and I would expect those to need different responses: a paid slot sits in a search engine's abuse queue, while an organic listing has to be pulled at the registrar or the host [6].
What to watch
- Whether Malwarebytes or Bitrefill publishes the domains and receiving addresses, which would let exchanges flag the wallets.
- Whether the placement turns out to be paid search advertising, putting the ad platforms' review process in scope.
- Whether the same cloned-checkout funnel appears against other merchants that accept cryptocurrency at checkout.