JAN3 pauses Indra forward swaps after denial-of-service attack
0
0

Within hours of the September 15, 2026 launch of the open beta version of Indra, the new Bitcoin swap system of JAN3, it became the victim of a denial-of-service (DDoS) attack. As the team was investigating the matter, they paused swap services temporarily. The attack was one more in the recent series of service interruptions connected with the Lightning infrastructure.
The incident puts the emphasis not so much on the current prices and performance of Bitcoin but on the durability of services created around it.
Samson Mow, the CEO of JAN3, reported the problem on X that day.
Indra is currently experiencing a DoS attack. To limit impact, we’ve temporarily disabled forward swaps while we investigate and mitigate.
— Samson Mow
He stated that swaps already underway may take longer to be completed and promised that more details will be posted soon.
What Indra is, and what it is not
AQUA has announced the beta version of Indra, a custom swap infrastructure that connects Bitcoin to Lightning and Liquid networks, on September 15. Mow said that JAN3 created the solution internally to replace Boltz as a service option for AQUA.
Indra is the solution we built in-house to replace Boltz in @AquaBitcoin.
— Samson Mow
According to Mow, Liquid pegging activities were being restored. However, certain limitations on liquidity will apply during operations.
It is worth noting that the incident targeted a provider-run swap service rather than the actual Bitcoin and/or the Lightning network. There is no indication of a failure at a protocol level.
A cluster of provider outages, not a protocol break
Indra follows a series of service interruptions that Cryptopolitan described from 3 to 5 August, 2026. Boltz has suspended swaps following months of automated, AI-assisted probing and numerous confined hacks; AQUA has signaled swap failures, while ZEUS has taken its infrastructure offline after an incident that it said was contained without loss of any client funds.
Nevertheless, the Lightning Network itself seems to have maintained its stability. Data from Amboss cited in the Cryptopolitan report indicated that on August 6, there were approximately 14,760 open Lightning nodes available to the public, while the public network capability has increased by 28 BTC within the week. This means that the failures have been concentrated at individual service providers rather than affecting the whole network.
An article published on August 7 adds to the understanding of the situation. In their analysis of data on Lightning Network topology from 2019 to 2023, the researchers concluded that the functionality of its routing backbone has remained stable despite the network becoming more structurally concentrated. On the other hand, the paper does not analyze the way the Lightning Network performs during an attack, and therefore its conclusions can’t be viewed as proof of the network’s resilience to an attack.
Why the service layer is now the pressure point
The wider security environment is becoming more complicated. Cloudflare’s report for the first half of the year recorded massive DDoS attacks above 1 Tbps and increases in DNS floods. NETSCOUT documented over 8 million DDoS attacks between July and December 2025 across 203 countries and regions, with attacks reaching 30 Tbps. The report also indicated that conversational AI and illicit language models are making complex attacks easier to conduct for less skilled operators.
Crypto is also witnessing the same transition. A security report indicates that infrastructure and supply-chain vulnerabilities led to losses of over $1.8 billion in terms of recorded crypto vulnerabilities since January 2025.
The level of importance grows because of more organizations and users are using cryptocurrencies. In Q1 2026, TRM Labs estimated the total retail crypto activity worldwide to be $979 billion. Deloitte, referring to estimates from the beginning of 2024, stated that there are more than 6,000 companies that accept Bitcoin as a means of payment.
Due to more and more users and enterprises using cryptocurrencies, outages are starting to be treated as an issue of adoption. Even if the protocol itself works properly, preventing various outages means increasing security costs, compelling service providers to make some additional investments, and weakening confidence in the services connecting users to the network.
What to watch next
According to Mow, JAN3 will keep updating its users on the progress of its attack resolution. The first questions are how long forward swaps will not be possible, whether in-flight swaps will experience serious disruptions, and what changes will be made by JAN3 before the transition past the open beta stage.
For the rest of the market, it gets simpler: whether swap and Lightning hosted services can handle attacks without affecting clients in the process.
The smartest crypto minds already read our newsletter. Want in? Join them.
0
0
Securely connect the portfolio you’re using to start.





