Swiss Bitcoin Pay Halts Servers After Bitcoin (BTC) Payment Data Breach
Swiss Bitcoin Pay shut down its servers after a suspected breach hit customer emails, Bitcoin addresses, IBANs and hashed passwords; user funds are safe.
AI SummaryAI
- Swiss Bitcoin Pay shut down its servers Monday after a suspected breach of internal systems.
- Breached data includes customer emails, Bitcoin addresses, IBANs, transaction history and hashed passwords.
- Follow-up post says small user balances are temporarily held due to daily, weekly or monthly Lightning batching.
- Revolut confirmed it passed passports, selfies and transaction histories to an unauthorized party last week.
Swiss Bitcoin Pay, a Neuchâtel-based non-custodial processor for Bitcoin (BTC) payments, took its servers offline on Monday after concluding that a malicious actor had likely gained access to its internal systems. The company announced the move through its official X account, describing the shutdown as a precaution taken while it investigates and secures its infrastructure. According to that statement, data believed to be affected includes customer email addresses, Bitcoin addresses, IBANs, transaction history and hashed passwords. The company stressed that user funds are safe and that any amounts owed to users will be returned in full.
The affected service lets merchants accept payments in Bitcoin through both base-layer transactions and the Lightning Network, routing value directly from customer to business instead of holding coins on the company's balance sheet. That architecture matters here: Monday's incident is a data breach rather than a custody failure, and no unauthorized Bitcoin transfers have been reported. The Neuchâtel-based firm markets itself to businesses that want to accept bitcoin without custody risk, and the shutdown leaves those merchants without a working payment rail until the infrastructure is secured. The breach disclosure stops short of naming the attacker's method; the company says the investigation is ongoing and did not specify the point of entry. The episode fits a broader run of breaches across the Bitcoin and crypto sector. Revolut confirmed last week that it handed customer passports, driver's licenses, verification selfies and transaction histories to an unauthorized party that had sent fraudulent requests from a legitimate government agency's email domain. Hardware wallet maker Trezor separately warned that a breach at the third-party marketing platform it uses for newsletters was fueling phishing attempts against its customers. Swiss Bitcoin Pay had not responded to a request for comment at the time of writing.
The company has not disclosed how many customers are affected, how the intruder gained access, whether the data was copied or merely viewed, or when services will come back online. One operational nuance has surfaced, however. In a follow-up post on X, Swiss Bitcoin Pay clarified that it briefly holds some user balances — generally small amounts — because incoming Lightning payments are batched and settled on-chain in daily, weekly or monthly cycles. With servers offline, those float balances are effectively frozen until the infrastructure is restored. For a payments business, the exposure is unusually sensitive: IBANs and transaction histories give an attacker a near-complete financial profile of each merchant, while hashed passwords invite offline cracking attempts against customers who reused credentials elsewhere. Security researcher Pasquale Pillitteri observed that the leaked fields, taken together, amount to ready-made material for a bespoke phishing campaign. He also flagged a longer-tail concern: affected users' Bitcoin addresses can now be correlated with real-world identities, allowing outside observers to trace their on-chain activity. The incident lands during a heavy stretch for data theft around digital assets. Blockstream's Liquid sidechain only resumed block production last week after a federation-wallet compromise in which roughly 4,000 BTC were reportedly withdrawn. Japan's digital agency separately disclosed that nearly 246,000 employee and contractor records may have leaked. Wallet provider SafePal last month reported unauthorized access to the order information of about 39,798 customers, including names, addresses and purchase data, and scammers obtained customer data through Global-e, the payment processor used by hardware wallet maker Ledger, back in January. Neither the attacker's identity nor any ransom demand has been confirmed publicly.
Our read: 2026's attackers are hitting the data plumbing around Bitcoin rather than its cryptographic core. Revolut, Trezor, SafePal and now Swiss Bitcoin Pay all leaked identity and account metadata while keys and custody stayed intact — which is precisely why the non-custodial design contained the damage. The company's own posts remain the authoritative record: they confirm no unauthorized Bitcoin movements so far, but also that the investigation is open and no restoration date has been set. For merchants, the near-term cost is downtime; for affected users, it is targeted phishing built from email, IBAN and address data. We expect a fuller post-incident report to identify the entry vector — until then, the metadata exposure is the confirmed damage.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


