Tag: Swiss Bitcoin Pay

  • Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Shuts Down Servers After Security Breach Exposes User Data

    Swiss Bitcoin Pay Takes Servers Offline After Security Breach Exposes User Data

    Swiss Bitcoin Pay, a cryptocurrency payment processing provider, took all its servers offline on Monday following a security incident that raised concerns about unauthorized access to internal systems. The company announced the breach via its official X account, stating that email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed user passwords may have been exposed.

    Company Response and Investigation Underway

    Despite the exposure of sensitive customer data, Swiss Bitcoin Pay assured users that no funds were at risk as a result of the incident. The company emphasized that it had not yet determined the full scope of the breach and disabled its servers as a precautionary measure while the investigation continues.

    As of publication, the firm has not disclosed how many customers were affected, the method used by the attacker to gain access, or whether any files were extracted or only viewed. No projected timeline for restoring services has been provided.

    Non-Custodial Design Limits Financial Exposure

    Swiss Bitcoin Pay highlighted that its non-custodial architecture prevents attackers from accessing customer funds directly, as payments flow from customer to merchant and remain isolated from internal systems. However, in a follow-up message on X, the company acknowledged it temporarily holds small user balances during routine operations.

    This temporary custody typically occurs when Lightning Network payments are aggregated into batch transactions for settlement via a single on-chain movement, executed daily, weekly, or monthly. The Lightning Network, a layer-2 protocol built on Bitcoin, enables fast and low-cost transactions by processing off-chain payment channels and settling only aggregate transactions on the main blockchain.

    Swiss Bitcoin Pay clarified that although this operational feature results in brief storage of customer assets, no unauthorized Bitcoin transactions have been identified in connection with the breach.

    Security Experts Warn of Phishing Risks

    Digital security experts have cautioned that the combination of stolen email addresses, Bitcoin addresses, bank IBANs, transaction histories, and hashed passwords poses a significant risk of targeted phishing attacks.

    Security analyst Pasquale Pillitteri described the exposed data as “textbook material for a tailored phishing attack” when these identifiers are combined.

    Another concern arises from the potential to link Bitcoin addresses to real-world identities, which could compromise user privacy and enable tracing of on-chain transaction histories.

    Context of Recent Industry Breaches

    The incident follows a series of high-profile data breaches in the digital asset sector that have heightened concerns about user data security. Blockstream’s Liquid Network was recently impacted by an exploit resulting in nearly 4,000 BTC being stolen. In a separate case, Japan’s Digital Agency reported a leak of 246,000 staff and contractor records, including names, email addresses, and phone numbers.

    Hardware wallet manufacturer Trezor also suffered a data breach exposing customer purchase and shipping information, while a flaw in a SafePal order-tracking plugin impacted nearly 40,000 users. Swiss Bitcoin Pay has not attributed its incident to any known vulnerability or similar exploit used in these earlier cases.

  • Swiss Bitcoin Pay Shuts Down Servers After Data Breach

    Swiss Bitcoin Pay Shuts Down Servers After Data Breach

    Swiss Bitcoin Pay Takes Servers Offline Following Data Breach

    Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, announced Monday that it had temporarily shut down its servers after detecting a data breach. The company stated that user funds remain secure, though customer email addresses, bitcoin addresses, IBANs, transaction histories, and hashed passwords are believed to have been compromised.

    Breach Details and Company Response

    According to a statement posted on X (formerly Twitter), the company confirmed that a malicious actor likely gained access to its internal systems. The full statement reads:

    “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.At this stage, we believe they may have accessed customer email addresses, Bitcoin…”

    In a follow-up announcement, Swiss Bitcoin Pay reiterated the situation and sought to reassure users:

    “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems …As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.” Swiss Bitcoin Pay said on Monday.

    “User funds are safe, and any amounts owed to users will be fully returned.”

    The company did not immediately respond to Bitcoin Magazine’s request for additional comment. Swiss Bitcoin Pay enables businesses to accept bitcoin payments using both on-chain transactions and the Lightning Network.

    Part of a Broader Trend in 2026

    The incident adds to a growing list of data breaches affecting bitcoin and fintech firms this year. Last week, Revolut confirmed it had provided customer passports, driver’s licenses, verification selfies, and transaction histories to an unauthorized party that sent fraudulent requests from a legitimate government agency’s email domain.

    Also last week, hardware wallet manufacturer Trezor warned customers that a data breach at a third-party marketing platform used for newsletter distribution had exposed user data, leading to targeted phishing attacks.

    Earlier in 2026, criminals obtained customer information through Ledger’s payment processor, Global-e, to conduct phishing campaigns. In August, crypto wallet provider SafePal disclosed a breach involving unauthorized access to approximately 39,798 customers’ order information, including names, addresses, and purchase data.