Comparison of crypto gift card platforms in 2026

Bitrefill Alternative 2026: Safer Ways to Buy Gift Cards With Crypto After the Breach

What Happened to Bitrefill in March 2026

On March 1, 2026, Bitrefill disclosed a cyberattack that took the platform offline and drained several of its crypto hot wallets. The company later attributed the breach to the Lazarus Group, a North Korea-linked threat actor known for targeting crypto infrastructure.

The Attack

The initial access came through a compromised employee laptop. Attackers extracted a legacy credential from that device, which gave them access to a snapshot containing production secrets. From there, they escalated into Bitrefill’s infrastructure, reaching parts of the database and several cryptocurrency wallets.

Bitrefill detected the breach after noticing suspicious purchasing patterns with certain suppliers. Gift card stock and supply lines were being exploited at the same time that funds were moving from hot wallets to attacker-controlled addresses. All systems were taken offline as part of the containment response.

What Data Was Exposed

Approximately 18,500 purchase records were accessed. Each record contained email addresses, crypto payment addresses, and IP metadata. For roughly 1,000 purchases where products required a name, that information may also have been exposed. Bitrefill stores minimal personal data and does not require full KYC, which limited the scope, but the exposure of crypto wallet addresses and IPs is still significant for a privacy-focused user base.

Is Bitrefill Safe to Use Now?

Bitrefill has since tightened internal access controls, conducted external pentests, and improved its monitoring. The platform is operational again. Whether that is enough depends on your risk tolerance. The breach did not expose gift card codes or stored account balances, which is relevant. But the fact that hot wallets were drained points to a custody model where user-deposited crypto sat in platform-controlled wallets, and that model was exploited.

What to Look for in a Crypto Gift Card Platform

The Bitrefill breach exposed specific architectural choices that users should evaluate when choosing any platform.

Custody Model

Ask whether the platform holds your crypto after you deposit or converts it immediately. Bitrefill held crypto in hot wallets, and that was the pool the attackers drained. Platforms that convert deposits to fiat at the moment of deposit reduce the attack surface. A platform that never holds your crypto has nothing for an attacker to drain.

Data Minimization

How much personal data does the platform collect and store? Email-only registration with no KYC is the baseline for crypto-native platforms. The less data stored, the less data exposed in a breach. Check whether the platform stores crypto wallet addresses and transaction metadata, because those can be used for on-chain tracking even without a name attached.

Pricing

Most crypto gift card platforms sell at face value. Some add a service fee on top. A few source from wholesalers at below-face-value rates and pass part of that discount to the buyer. The difference is small per transaction (typically 3-6%) but compounds for regular buyers and resellers.

Delivery

Fully automated delivery after on-chain confirmation is the baseline for crypto gift card platforms. Manual processing implies humans between the wholesaler and the buyer, which adds latency and internal touchpoints. An automated pipeline keeps the path from order to code short and consistent, which is the architecture you want regardless of security context.

Bitrefill Alternatives Compared

Here is how the main platforms compare as of April 2026.

Feature Rekodo CoinsBee CryptoRefills SpendCrypto
Catalog size 9,000+ products, 2,500+ brands 5,000+ brands 5,000+ brands Top 20-30 brands
Pricing ~5% below face value (tier-dependent) At or near face value At or near face value Face value, no added fee (FX spread on non-stablecoins)
Accepted crypto USDT/USDC on Polygon, Solana, BSC, Ethereum, TRON. Binance Pay supported 200+ coins. Binance Pay, Crypto.com Pay 100+ coins. Lightning, Polygon, Solana, TRON, Avalanche, Optimism, Base, BSC, Arbitrum, TON, SUI BTC, ETH, USDT, LTC
KYC required Email only Email only No account needed Email only
Custody model Crypto converts to USD at deposit Not publicly disclosed Not publicly disclosed Not publicly disclosed
Loyalty tiers Retail, Reseller, Wholesale No No No
Delivery Automatic after on-chain confirmation Automatic Automatic Automatic
Geographic coverage Global access, product-level regional redemption 185+ countries 180+ countries Limited regions
Wholesaler Tier-1 wholesaler Multiple Multiple Not disclosed

Rekodo

Rekodo sources from a tier-1 gift card wholesaler. The pricing model is different: instead of selling at face value, Rekodo passes part of the wholesale discount to the buyer. On PSN USA gift cards, for example, the discount runs around 5% below face value at the entry-level Retail tier, with better rates for Reseller and Wholesale tiers.

The custody model is the most relevant differentiator post-breach: crypto deposits convert to USD in the user’s wallet at the moment of deposit. The platform does not hold crypto in hot wallets. Delivery is automatic after on-chain confirmation.

CoinsBee

German-based platform with 5,000+ brands across 185+ countries. Accepts 200+ cryptocurrencies plus Binance Pay and Crypto.com Pay, which makes it the strongest choice for holders of less common altcoins. Reports over 500,000 registered users. Pricing is at or near face value.

CryptoRefills

5,000+ brands, 180+ countries, 100+ cryptocurrencies accepted including Bitcoin Lightning Network. Networks supported span Polygon, Solana, TRON, Avalanche, Optimism, Base, BSC, Arbitrum, TON, and SUI, so coverage for newer L2s and emerging chains is broader than most peers. No account required for purchases. Pricing at face value.

SpendCrypto

Focused on the top 20-30 most popular gift card brands. Prices at face value with no added service fee on top of the card price. For non-stablecoin payments (BTC, ETH, LTC), a FX spread of roughly 1% applies to the crypto-to-fiat conversion, so the effective cost includes that spread. Reviews on Trustpilot report the BTC rate as tighter than Bitrefill’s. Limited geographic coverage.

Others Worth Noting

BitPay offers gift cards through its wallet app with a good selection of US brands. eGifter accepts Bitcoin via BitPay integration. Bidali supports a wide range of stablecoins. None of these have the catalog depth or below-face-value pricing of the top four, but they serve specific niches.

How Rekodo Addresses the Custody Problem

The Bitrefill breach succeeded in part because the platform held cryptocurrency in hot wallets that were accessible from compromised infrastructure. Rekodo’s architecture avoids this specific vector.

USD Wallet, Not Crypto Hot Wallets

When you deposit USDT or USDC into Rekodo, the crypto converts to a USD balance in your wallet immediately. From that point forward, your funds exist as a USD ledger entry, not as crypto sitting in a platform-controlled wallet. There is no pool of user crypto for an attacker to drain because the crypto does not persist on the platform after deposit.

Same Wholesaler, Different Economics

Rekodo and Bitrefill operate in the same tier of the gift card supply chain, sourcing directly from major wholesalers rather than reselling P2P. The catalog overlap is extensive: 9,000+ products across 2,500+ brands covering gaming (PSN, Xbox, Steam, Nintendo), streaming (Netflix, Spotify, Disney+), retail (Amazon, Google Play, Apple), and dozens of other categories.

The pricing difference comes from how the wholesale discount is distributed. Bitrefill sells at face value and keeps the full margin. Rekodo passes part of the discount to the buyer, with better rates at higher loyalty tiers. For a buyer spending $100/month on PSN gift cards, the ~5% savings adds up to roughly $60/year at the entry tier, more at Reseller and Wholesale.

Automatic Delivery End to End

Rekodo’s delivery is fully automated. An order placed triggers a direct call to the wholesaler API, and the code lands in the user panel and email after on-chain confirmation of the deposit. No human touches the stock between the wholesaler and the buyer. The pipeline is short and consistent, which is the architecture the product was designed around from day one.

Choosing the Right Platform

No platform is immune to attacks. What you can evaluate is how much damage an attack would cause, and that depends on architecture choices made before the breach happens.

If pricing matters and you buy regularly, Rekodo’s below-face-value model and loyalty tiers offer concrete savings. If you hold less common altcoins, CoinsBee’s 200+ supported tokens makes it the broadest option. If you need access in markets where other catalogs are thin, CryptoRefills’ 180+ country coverage and support for Lightning plus L2s like Optimism, Base, and Arbitrum fills gaps that others leave open.

The common thread: check how the platform handles your crypto after deposit, how much data it stores, and whether delivery depends on human processing. Those are the three things that determined the impact of the Bitrefill breach, and they will determine the impact of the next one.


Published April 2026. Pricing and platform details reflect conditions at the time of writing and may change. Verify current rates on each platform before purchasing.

Preguntas frecuentes

Is Bitrefill safe to use after the hack?

Bitrefill has improved its security since the March 2026 breach, but the fact that hot wallets were drained and 18,500 purchase records were exposed means the risk tolerance is personal. If custody model matters to you, look for platforms that convert crypto to fiat immediately rather than holding it in hot wallets.

What is the cheapest Bitrefill alternative?

Rekodo sources directly from tier-1 wholesalers and prices gift cards around 5% below face value on supported brands. SpendCrypto prices at face value with no added fee. CoinsBee and CryptoRefills typically sell at or near face value.

Can I buy gift cards with USDT without KYC?

Yes. Rekodo, CryptoRefills, and CoinsBee all accept USDT without invasive KYC. Rekodo requires email verification only. No identity documents needed.

What happened to Bitrefill in March 2026?

On March 1, 2026, attackers gained access through a compromised employee laptop and escalated to production systems. They drained hot wallets and accessed 18,500 purchase records including emails, crypto addresses, and IPs. Bitrefill attributed the attack to the Lazarus Group.

Does Rekodo use the same supplier as Bitrefill?

Yes. Both operate at the same level of the supply chain, sourcing directly from major wholesalers with 9,000+ products and 2,500+ brands. The difference is in pricing model and custody: Rekodo offers below-face-value pricing with loyalty tiers and converts crypto to USD immediately upon deposit.

How do loyalty tiers work on Rekodo?

Tier progression is volume-based. All users start at Retail. When purchase history reaches a threshold, the account is reviewed and upgraded to Reseller or Wholesale, each with better pricing. There is no separate B2B application.