Next Solution claims Thrill drop codes into your own account for you. We never store your Thrill password, 2-factor code, or email.
How it works: you connect your Thrill account and we store its session token (encrypted at rest with AES-256-GCM). Our server then redeems codes directly into your account — you never handle raw codes. Disconnect at any time and the stored token is deleted. Two ways to connect: the browser connector reads only your existing session, so it never sees a password at all; or, from a phone, the Telegram bot logs you in once — you enter your password and 2-factor code, they are used to sign in and never stored, and each message is deleted from the chat the moment it is used.
Why a stored session can't drain your account: we only keep sessions that are protected by an authenticator app (2-factor), and Thrill requires that same code for every withdrawal — a code we never hold. So the session we store can claim drop codes but cannot move your funds. As with any hosted service, a compromise of our servers or database could expose a connected session (letting it claim codes, not withdraw) — use the hosted connector only if you accept that, and disconnect when you're done.
Use at your own risk. We do not guarantee that any code is valid, unclaimed, or claimable, and we are not responsible for how any third party treats automated redemption.
Credits and activated access windows are non-refundable.
One key is bound to one device. Sharing a key will lock it.
Pay in crypto. Payments are final once confirmed on-chain.