Swiss Bitcoin Pay says customer data may have been exposed after unauthorized access to internal systems
Swiss Bitcoin Pay has temporarily shut down its servers after what it described as unauthorized access to its internal systems. The company says attackers may have obtained customer email addresses, Bitcoin addresses, IBANs, transaction history, and hashed passwords — the kind of breach that matters for high-risk payments even when the funds themselves are not held by the provider.
- In a post on X dated September 14, 2026, Swiss Bitcoin Pay said a “malicious user” had likely gained access to its internal systems. The company said it was shutting down servers “as a precaution” while it investigates and secures the infrastructure.
- The provider said the attackers may have accessed customer email addresses, Bitcoin addresses, IBANs, transaction history, and hashed passwords. It also said it has not yet established whether any other information was exposed.
- Swiss Bitcoin Pay did not say how the attackers got in, how many customers may have been affected, or when service will resume. The company said it does not have a reopening date yet and is working to secure the system “as quickly as possible.”
- The company said customer funds are safe and that any amounts owed to users will be fully returned. It also said it has not found signs that merchant private keys were compromised or that Bitcoin was withdrawn from users’ non-custodial wallets.
- The structure of Swiss Bitcoin Pay’s business is the important part here: unlike a custodial exchange, it does not hold customer funds on behalf of users. Bitcoin received by merchants through the service goes to wallets they control. That limits the blast radius of a systems breach, but it does not remove the payment-data problem.
Swiss Bitcoin Pay also acknowledged a specific operational risk around Lightning Network payments. It said incoming payments made through Bitcoin’s second-layer network can remain in its systems for a period before being sent on-chain, though the company says those amounts are usually small. For PSPs and merchants, the takeaway is straightforward: non-custodial flow does not mean zero exposure, especially when customer identifiers and payment history are sitting in the provider’s internal systems.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!