Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, pulled its servers offline on Monday after discovering what it believes was a data breach. The company posted on X that a malicious user had likely gained access to its internal systems, and that it was shutting things down as a precaution while it investigates.
The firm said customer email addresses, bitcoin addresses, IBANs, transaction history, and hashed passwords were believed to be exposed. But user funds, it stressed, are safe, and any amounts owed to users will be fully returned. That distinction matters because the company is non-custodial, meaning it does not hold customers' bitcoin directly.
What it stores are the identity and payment details tied to its processing service.
The company lets businesses accept bitcoin payments quickly using both on-chain transactions and the Lightning Network, a faster payment layer built on top of bitcoin. So the breach hit the business-facing infrastructure rather than a vault of customer coins.
Bitcoin Magazine reported that Swiss Bitcoin Pay did not immediately respond to its request for comment. The article, written by Mathew Di Salvo and published September 14, 2026, drew on the company's own public statement posted to X on the same day.
The incident lands in the middle of a rough stretch for data security across crypto and fintech. Revolut confirmed last week that it handed customer passports, driver's licenses, verification selfies, and transaction histories to an unauthorized party that sent fraudulent requests using a legitimate government email domain.
And Trezor, a major hardware wallet maker, warned last week that a breach at its third-party marketing platform was leading criminals to target customers with phishing emails.
Going further back, scammers got hold of customer information through crypto wallet Ledger's payment processor Global-e in January, and SafePal disclosed a breach last month involving about 39,798 customers' order information, including names and addresses.
So Swiss Bitcoin Pay is not an isolated case, and the pattern suggests attackers are targeting the weak points in the payment chain rather than the blockchains themselves.
Bitcoin was trading around $79,325 at the time of the announcement, according to CoinGecko data, up roughly 2.6% over the prior 24 hours. The token has recovered about 26% over the past month after a sharp drawdown from its October 2025 high near $126,080.
The company's statement did not say how long the servers would stay down, or how long the investigation would take. It also did not say whether law enforcement had been contacted. Swiss Bitcoin Pay has not immediately responded to Bitcoin Magazine's follow-up questions, so the timeline remains unclear.
The immediate practical question is whether affected customers need to take action. Because hashed passwords were among the compromised data, anyone who reused passwords on other services should change them. And because email addresses and IBANs were exposed, phishing attempts targeting Swiss Bitcoin Pay users are likely in the days ahead.
Reader desk
Discuss the signal
Verified readers · 2 comments per post / 24h
No comments yet. Be the first verified reader to add context.