Swiss Bitcoin Pay, a provider of cryptocurrency payment processing solutions, took all its servers offline on Monday following an incident that raised concerns its internal systems had been accessed by an intruder.
Security breach and response
The company stated that email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed user passwords may have been exposed during the breach. Despite the exposure of sensitive data, Swiss Bitcoin Pay assured its customers that no funds were at risk as a result of the incident.
Swiss Bitcoin Pay announced via its official X account that it had not determined the full scope of the breach yet. The company decided to disable its servers as a precautionary measure while the investigation continues.
As of now, the firm has not disclosed how many customers were affected, the method used by the attacker to gain access, or whether any files were extracted or only viewed by the intruder. The company has not provided a projected timeline for restoring services.
Swiss Bitcoin Pay emphasized that its non-custodial design prevents attackers from accessing customer funds, as payments flow directly from customer to merchant and are isolated from its internal systems.
However, in a follow-up message on X, the company acknowledged that it temporarily holds small user balances. This typically occurs when Lightning Network payments are aggregated into batch transactions to be sent with a single on-chain movement, executed daily, weekly, or monthly.
Swiss Bitcoin Pay clarified that although this operational feature results in the brief storage of customer assets, no unauthorized Bitcoin transactions have been identified in connection with the breach.
Mini dictionary: Lightning Network, a layer-2 protocol built on Bitcoin, enables fast and low-cost transactions by processing off-chain payment channels and settling only aggregate transactions on the main blockchain.
Potential implications for users
Digital security experts have cautioned that the combination of stolen email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed passwords poses a significant risk of targeted phishing attacks.
Security analyst Pasquale Pillitteri described the exposed data as “textbook material for a tailored phishing attack” when these identifiers are combined.
Another risk arises from the potential to connect Bitcoin addresses to real names, which could compromise privacy and allow tracing of users’ on-chain transaction histories.
Recent high-profile breaches in the digital asset sector have heightened concerns about user data security. Blockstream’s Liquid Network was recently impacted by an exploit that resulted in nearly 4,000 BTC being stolen. In a separate case, Japan’s Digital Agency reported a leak of 246,000 staff and contractor records, including names, email addresses, and phone numbers.
Hardware wallet company Trezor also suffered a data breach, exposing purchase and shipping information of customers, while a flaw in a SafePal order-tracking plugin impacted nearly 40,000 users. Swiss Bitcoin Pay has not attributed its incident to any known vulnerability or similar exploit used in these earlier cases.




