Swiss Bitcoin Pay pulls servers offline after suspected internal breach
0
0

Swiss Bitcoin Pay shut down its entire server infrastructure on Monday after concluding that an intruder had probably reached its internal systems.
The firm is warning that customer email addresses, Bitcoin addresses, bank IBANs, transaction histories and hashed passwords may have been exposed. Despite this, the company says no customer money is at risk.
Why did Swiss Bitcoin Pay take its servers offline?
Swiss Bitcoin Pay revealed on its official account on X that the team is still working out what it is dealing with after a malicious user reportedly gained access to the firm’s internal systems. The post stated that the servers were being shut down “as a precaution” during the investigation.
Swiss Bitcoin Pay has not said how many customers are affected, how the attacker got in, or whether data was copied out or merely viewed. It has also not given a date for the resumption of its services.
Swiss Bitcoin Pay’s non-custodial design functions by letting payments pass straight from customer to merchant. With this system, customer funds are completely walled off from the compromised systems, and no unauthorized Bitcoin movements have been identified.
However, in a follow-up reply on X, Swiss Bitcoin Pay explained that it does briefly hold some user balances, even though they are “generally” small amounts.
The firm explained that this happens because it sorts incoming Lightning payments into batches so they can be handled with a single on-chain output on a daily, weekly or monthly cycle.
How much damage can the Swiss Bitcoin hack cause?
Cryptopolitan reported that Blockstream’s Liquid sidechain only resumed block production last week following a hack in which close to 4,000 BTC was drained from its federation wallet.
Days before that, Japan’s Digital Agency disclosed that roughly 246,000 records of staff and contractors, including names, emails and phone numbers, may have leaked.
The customer email addresses, Bitcoin addresses, bank IBANs, transaction histories and hashed passwords that are feared stolen from Swiss Bitcoin Pay become, in the words of Pasquale Pillitteri, “textbook material for a tailored phishing attack” when combined.
Furthermore, users compromised by the exposure can now have their Bitcoin addresses linked to real names, letting anyone trace that person’s on-chain activity.
A recent breach at hardware-wallet maker Trezor also spilled buyers’ contact and shipping details. A separate SafePal incident hit 39,798 customers through a flawed order-tracking plugin. Swiss Bitcoin Pay has not tied its own case to any specific vulnerability.
The smartest crypto minds already read our newsletter. Want in? Join them.
0
0
Securely connect the portfolio you’re using to start.





