A Swiss-based Bitcoin payment processor has shut down access to its platform after detecting malicious activity on its internal systems. Sensitive customer data may have been compromised.
The incident raises critical questions about the security of non-custodial infrastructure, often marketed as safer than centralized exchanges. The reality, as it turns out, is more nuanced.
Here is what we know so far, and what it means for the merchants and users affected.
Internal Breach at Swiss Bitcoin Pay: What Happened
Swiss Bitcoin Pay, a company founded in late 2022 and headquartered in Neuchâtel, operates as a non-custodial Bitcoin payment processor for merchants, supporting both on-chain transactions and the Lightning Network. On September 15, 2026, the company announced via X that it had temporarily taken all of its servers offline after detecting that a malicious actor had likely gained access to its internal systems.
According to the company’s official statement, the data potentially exposed includes: email addresses, Bitcoin addresses, IBANs, transaction histories, and hashed passwords. The company notes that it has not yet been established whether additional data was affected, and that the investigation remains ongoing.
On the financial side, Swiss Bitcoin Pay has confirmed that user funds are safe and that any outstanding amounts will be returned in full. The service’s non-custodial architecture — whereby payments are routed directly to merchants’ wallets — mechanically limits exposure to fund losses. No reopening date has been communicated at this stage.
Why This Incident Goes Beyond a Simple Security Bug

The most concerning aspect of this incident is not the loss of funds — which, at this stage, appears to be nonexistent — but rather the nature of the data exposed. The combination of Bitcoin addresses, IBANs, and transaction histories amounts to a complete financial profile. This type of data can be exploited for targeted phishing attacks, social engineering, or, in the most serious cases, physical extortion attempts — the notorious so-called “$5 wrench attacks.”
The fact that passwords were hashed is a sound security practice, but it does not guarantee their integrity if weak hashing algorithms or insufficient salts were used. Swiss Bitcoin Pay has not yet disclosed the hashing method employed — information that affected users are fully entitled to demand.
This incident also serves as a reminder that the non-custodial model protects funds, but not necessarily financial metadata. In an ecosystem where privacy is a core value, the centralization of KYC and transactional data remains a structural attack vector, regardless of the asset custody model in place.
What Swiss Bitcoin Pay Users Should Do Right Now
If you use or have previously used Swiss Bitcoin Pay, several steps should be taken immediately, without waiting for the investigation to conclude. First and foremost, change your password immediately on any platform where you use the same credentials — password reuse remains one of the most widely exploited attack vectors. Enable two-factor authentication (2FA) wherever it is available.
Next, closely monitor any Bitcoin addresses linked to the platform. While funds have been declared safe, maintaining heightened vigilance over incoming and outgoing transactions is strongly advised. If you have associated an IBAN with your account, notify your bank of the incident as a precautionary measure.
Finally, be wary of any unsolicited contact in the coming weeks — phishing emails, fake technical support messages, or social media outreach claiming to come from Swiss Bitcoin Pay. The company has stated that it will communicate exclusively through its official X account for the duration of the investigation.