Invest1 publisher2 min readPublished
Swiss Bitcoin Pay pulled its whole server fleet offline over five fields of customer data
The payment firm says its servers went dark on September 14 after an intruder probably reached internal systems, and that customer emails, IBANs, transaction histories and hashed passwords may have been exposed.
The Investor · Invest desk

What happened
- Swiss Bitcoin Pay shut down its entire server infrastructure on Monday, September 14, after concluding that an intruder had probably reached its internal systems.
- The firm says the possibly exposed data covers customer email addresses, Bitcoin addresses, bank IBANs, transaction histories and hashed passwords.
- No unauthorized Bitcoin movements were identified, and the company says its non-custodial design passes payments straight from customer to merchant, keeping funds off the compromised systems.
- The company has not said how many customers are affected, how the attacker got in, whether data was copied out or only viewed, or when the service will come back.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure The customers newly reachable are the ones whose bank identifier and email address sat in the same record. A message that quotes a real past payment does not have to be persuasive to work.
- contradiction The non-custodial description and the company's own admission that it holds user balances between batches cannot both cover the same day. Sizing which one applied on September 14 needs a balance figure the firm has not given.
- decision Merchants taking Lightning payments through the service have to route them somewhere else while the infrastructure stays dark, and with no restoration date they are choosing a replacement rather than waiting.
Swiss Bitcoin Pay said in a follow-up reply on X that it does briefly hold some user balances, "generally" small amounts. That is because it sorts incoming Lightning payments into batches, so each batch can be settled with a single on-chain output on a daily, weekly or monthly cycle [7][8]. A daily cycle holds a user's money for about a day. A monthly one holds it for roughly thirty [2].
The company also said any amounts owed to users will be refunded in full [9]. The size of the balances sitting in those batches when the servers went dark is missing from Cryptopolitan's account.
Four of the five data categories the company listed describe where a person banks and where they transact; the fifth is a hashed credential [2][1]. Put together, they become "textbook material for a tailored phishing attack", in the words of Pasquale Pillitteri [10]. Cryptopolitan also notes that a customer whose Bitcoin address is now attached to a real name can have that on-chain activity traced by anyone looking [11].
The same report runs through four other cases. Blockstream's Liquid sidechain resumed block production last week after a hack drained close to 4,000 BTC from its federation wallet [12]. Japan's Digital Agency said roughly 246,000 staff and contractor records may have leaked [13]. A Trezor breach spilled buyers' contact and shipping details [14], and a SafePal incident reached 39,798 customers through a flawed order-tracking plugin [15]. Of those four, one lost coins and three lost customer files [3]. Swiss Bitcoin Pay has not tied its own case to any specific vulnerability [16].
I'd expect most of the cost here to arrive months after the servers come back, in messages that quote a customer's own IBAN and a real past transaction [2]. The company's counter-case is a serious one: the passwords were hashed, the intruder may only have viewed the file, and the amounts inside a batch window are small [2][6][7]. An affected-customer count, the hashing scheme, and forensic evidence that nothing was copied out would bring this back down to a service outage [6].
What to watch
- Whether Swiss Bitcoin Pay publishes forensic evidence showing the data was only viewed and not copied out.
- Whether phishing attempts quoting customers' own IBANs or past payments surface once the service returns.
- Whether the firm discloses the size of the user balances held between Lightning batches.