Tag: Security breach

  • Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Takes Servers Offline After Security Breach Exposes User Data

    Swiss Bitcoin Pay, a cryptocurrency payment processing provider, took all its servers offline on Monday following a security incident that raised concerns about unauthorized access to internal systems. The company announced the breach via its official X account, stating that email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed user passwords may have been exposed.

    Company Response and Investigation Underway

    Despite the exposure of sensitive customer data, Swiss Bitcoin Pay assured users that no funds were at risk as a result of the incident. The company emphasized that it had not yet determined the full scope of the breach and disabled its servers as a precautionary measure while the investigation continues.

    As of publication, the firm has not disclosed how many customers were affected, the method used by the attacker to gain access, or whether any files were extracted or only viewed. No projected timeline for restoring services has been provided.

    Non-Custodial Design Limits Financial Exposure

    Swiss Bitcoin Pay highlighted that its non-custodial architecture prevents attackers from accessing customer funds directly, as payments flow from customer to merchant and remain isolated from internal systems. However, in a follow-up message on X, the company acknowledged it temporarily holds small user balances during routine operations.

    This temporary custody typically occurs when Lightning Network payments are aggregated into batch transactions for settlement via a single on-chain movement, executed daily, weekly, or monthly. The Lightning Network, a layer-2 protocol built on Bitcoin, enables fast and low-cost transactions by processing off-chain payment channels and settling only aggregate transactions on the main blockchain.

    Swiss Bitcoin Pay clarified that although this operational feature results in brief storage of customer assets, no unauthorized Bitcoin transactions have been identified in connection with the breach.

    Security Experts Warn of Phishing Risks

    Digital security experts have cautioned that the combination of stolen email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed passwords poses a significant risk of targeted phishing attacks.

    Security analyst Pasquale Pillitteri described the exposed data as “textbook material for a tailored phishing attack” when these identifiers are combined.

    Another concern arises from the potential to link Bitcoin addresses to real-world identities, which could compromise user privacy and enable tracing of on-chain transaction histories.

    Context of Recent Industry Breaches

    The incident follows a series of high-profile data breaches in the digital asset sector that have heightened concerns about user data security. Blockstream’s Liquid Network was recently impacted by an exploit resulting in nearly 4,000 BTC being stolen. In a separate case, Japan’s Digital Agency reported a leak of 246,000 staff and contractor records, including names, email addresses, and phone numbers.

    Hardware wallet manufacturer Trezor also suffered a data breach exposing customer purchase and shipping information, while a flaw in a SafePal order-tracking plugin impacted nearly 40,000 users. Swiss Bitcoin Pay has not attributed its incident to any known vulnerability or similar exploit used in these earlier cases.

  • Chainflip Loses 736,442 USDT in TRON Exploit

    Chainflip Loses 736,442 USDT in TRON Exploit

    Chainflip Loses $736,442 in USDT Through TRON Memo Exploit

    Cross-chain protocol Chainflip suffered a security breach resulting in the loss of 736,442.17 USDT after an attacker exploited how the platform processes TRON transaction memos. The incident occurred during the early hours of September 12, prompting the protocol to pause operations while developers investigated and prepared a fix, according to a September 13 incident update.

    An update on yesterday’s exploit affecting Tron $USDT.736,442.17 $USDT was taken. All other funds are unaffected and secure, and impacted users will be made whole.The network stays paused while we finalise the fix and the restart plan.Full update: https://t.co/LTWSqLBOn3
    — CHAINFLIP (@Chainflip) September 13, 2026

    How the TRON Memo Exploit Worked

    Unlike other supported blockchains where Chainflip receives swap instructions through dedicated contract functions, the protocol’s TRON USDT integration relies on transaction memos to read swap instructions attached to TRON transfers. According to the incident report, the attacker discovered a method to attach a new memo to a transaction that Chainflip validators had already signed.

    The protocol’s systems interpreted the added memo as a separate swap instruction. When this new instruction appeared to fail, Chainflip issued a refund — but the original deposit had already produced a payout. Processing the altered memo therefore caused the protocol to pay against the same deposit a second time.

    Chainflip attributed the flaw to its own processing of TRON transaction memos and confirmed that the TRON blockchain, the USDT smart contract, and Tether’s reserve system were not compromised.

    Attack Timeline and Detection

    The attacker repeated the exploit method eight times over approximately 90 minutes. Early attempts used small amounts, with each subsequent attempt nearly doubling the previous one. Only six attempts produced unauthorized payouts totaling 736,442.17 USDT.

    The protocol detected the incident after subsequent USDT payments began failing. Developers traced the failures to the repeated processing of deposits through altered memos. Chainflip suspended network activity to examine whether the vulnerability could affect other assets or integrations. A preliminary review found the exploit was limited to TRON USDT, with remaining vault funds secure.

    The project described this as its first critical security event involving funds taken from protocol vaults, noting that earlier operational problems had not caused comparable losses.

    User Impact and Repayment Plans

    One legitimate user swap worth 115,654.41 USDT remains unpaid, though the funds are still held in Chainflip’s vault and can be released after the network restarts. This transaction is not counted among the six unauthorized payouts.

    Chainflip stated that affected users would be made whole, though the reimbursement method had not been selected or published as of September 13. Several options remain under review. The protocol has notified relevant parties about the stolen funds to track or recover proceeds as they move between addresses and services, but did not name those parties or confirm whether any USDT had been frozen.

    Tether can freeze addresses holding its tokens when acting under applicable legal or enforcement processes. No public statement from Tether or TRON concerning the Chainflip attack had been identified by publication time.

    Network Restart Targeted for Monday

    Chainflip reported that the underlying fix had been completed, but developers still needed to finalize the exact restart procedure. The network will remain paused “until Monday at the earliest,” making September 14 the earliest possible restoration date rather than a confirmed launch time.

    Before reopening, the team plans to finalize a technical restart plan designed to avoid further processing problems. Chainflip has not disclosed whether validators will need new software, a coordinated upgrade, or a governance vote.

    Once the system resumes, the protocol expects to process the pending 115,654.41 USDT swap and begin handling compensation for users whose funds were paid to the attacker. A complete technical report will follow after the restart plan is locked down and the network is operating securely, though no publication deadline has been announced.

  • Liquid Hackers Call Blockstream ‘Delusional, Greedy, and Arrogant,’ Demand 10% Bounty

    Liquid Hackers Call Blockstream ‘Delusional, Greedy, and Arrogant,’ Demand 10% Bounty

    Blockstream-Hacker Dispute Escalates Over Liquid Sidechain Security Breach

    The conflict between Blockstream and the party claiming to be a white-hat hacker has intensified, according to a recent update from Samson Mow. The hacker has leveled serious accusations against Blockstream, alleging the company dedicated only $1.5 million—or possibly nothing—to secure approximately $5 billion in assets on the Liquid sidechain.

    Hacker Demands Bounty, Threatens Further Losses

    In a message characterized by harsh language, the hacker labeled Blockstream’s approach a “flagrant neglect of security.” The group demanded that Blockstream pay a 10% bug bounty from its own funds and warned that refusal could lead to a 15% loss for Liquid users. The communication further accused Blockstream of being “delusional, greedy, and arrogant” in its security management. The hackers also stated they intend to publish the private key required to decrypt their conversations with the company.

    Meanwhile, the Liquid sidechain remains paused. Blockstream and Federation members are working on additional security fixes, resolving a chain split, and preparing for a coordinated network restart. Users have been advised not to send Bitcoin to Liquid peg-in addresses until the network is fully operational again.

    Background: $320 Million Withdrawal and Partial Return

    The latest exchange follows the withdrawal of roughly 4,000 BTC (valued at approximately $320 million at the time) from Liquid’s Federation wallet on September 6. The party responsible initially identified as white-hat hackers, stating the funds would be returned once Blockstream addressed the security vulnerability and patched all affected nodes. After Blockstream confirmed the bridge nodes had been patched, 3,400 BTC was returned to the Federation wallet, leaving approximately 598 BTC still in the hackers’ possession.

    Mow Warns of Serious Consequences

    In a separate post on X, former Blockstream Chief Strategy Officer Samson Mow cautioned the hackers that they may be underestimating the repercussions of their actions. He noted that Blockstream’s decision to engage with them via PGP encryption was a “courtesy” and questioned whether publicly admitting to taking the BTC and then demanding a bounty was a “wise move.”

    Mow further suggested the group left behind more forensic clues than they realize and warned that returning the funds does not guarantee they can simply walk away from the incident.

    “As a white hat, the road only widens; as a black hat, you’re forever on edge. Dreaming of walking away with assets unscathed is nothing but delusion. Some doors, once opened, can never be closed again.”