BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Non-Custodial Bitcoin Processor Halted After Data Breach

A Neuchâtel, Switzerland-based non-custodial digital asset payment processor was forced to take its servers offline on Monday after detecting a security breach that compromised a wide range of sensitive customer data. The platform temporarily halted operations as an immediate security measure to assess the unauthorized entry.

Swiss Bitcoin Pay, a firm that enables businesses to quickly and easily accept Bitcoin payments utilizing both on-chain transactions and the Lightning Network, confirmed the temporary shutdown to investigate the incident. While the company stated that user funds remained untouched, the breach exposed a significant amount of personal and financial information.

According to the firm, the compromised data is believed to include customer email addresses, Bitcoin addresses, international bank account numbers (IBANs), hashed passwords, and detailed transaction histories.

Despite the data exposure, the processor emphasized that client capital was secure. “User funds are safe, and any amounts owed to users will be fully returned,” the company stated in a Monday announcement regarding the incident.

The firm further explained its immediate response to the threat, stating: “A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems …As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure.”

The payment processor did not immediately respond to a request for comment from Bitcoin Magazine regarding the timeline for restoring operations.

Broader Industry Targeting

Non-Custodial Bitcoin Processor Halted After Data Breach
Photo: Pexels (server infrastructure).

The latest incident adds to a growing list of security breaches hitting digital asset and financial technology firms. Criminals have increasingly been targeting data in 2026, finding vulnerabilities in both direct corporate infrastructure and third-party service providers.

Just last week, the hardware wallet manufacturer Trezor issued a warning to its user base regarding a separate data breach. The compromise occurred at a third-party marketing platform utilized by Trezor for distributing company newsletters. Following this structural failure, criminals were able to target the wallet manufacturer’s customers with phishing attacks.

Similarly, fintech company Revolut confirmed last week that it had inadvertently handed over sensitive customer information to an unauthorized party. Malicious actors managed to execute the breach by sending fraudulent requests originating from an email domain belonging to a legitimate government agency. This resulted in the unauthorized party obtaining customer passports, driver’s licenses, verification selfies, and transaction histories.

Wallet Providers Hit

Other hardware and software wallet providers have also navigated significant data exposure incidents earlier in the year.

In January, scammers successfully acquired customer information associated with Ledger, another major hardware wallet manufacturer. The attackers compromised Ledger’s payment processor, Global-e, utilizing the extracted data to distribute phishing emails to affected users.

Last month, the crypto wallet provider SafePal also publicly disclosed a data breach affecting its user base. That incident involved an unauthorized actor gaining access to the order information of approximately 39,798 customers. The exposed data included sensitive personal details such as customer names, physical addresses, and specific purchase data.

← All stories