Swiss Bitcoin Pay, a non-custodial Bitcoin payment processor founded in late 2022, took its servers offline on Monday, Sept. 14, 2026, after disclosing that a malicious user likely gained unauthorized access to its internal systems, potentially exposing customer emails, Bitcoin addresses, IBANs, transaction histories and hashed passwords.
The company announced the incident through its official X account, warning customers that the investigation was still underway.
“A malicious user has likely gained access to Swiss Bitcoin Pay’s internal systems. As a precaution, we are temporarily shutting down our servers while we investigate and secure our infrastructure,” — Swiss Bitcoin Pay, in a statement posted on X.
The company subsequently outlined the categories of information it believed could have been accessed. The potentially exposed information includes customer email addresses, Bitcoin addresses, IBANs, transaction histories and hashed passwords.
The disclosure means the full scope of the incident remains uncertain. Swiss Bitcoin Pay has not indicated how the unauthorized user gained access, identified the individual or group responsible, or confirmed whether all of the listed information was actually extracted from its systems.
For customers, the incident is significant because information such as email addresses, Bitcoin addresses and banking details can potentially be used in targeted phishing or social-engineering attempts, even where cryptocurrency funds themselves are not compromised.
Swiss Bitcoin Pay says customer funds remain safe
Despite taking its infrastructure offline, Swiss Bitcoin Pay said the incident had not compromised customer funds. The company emphasized that users’ assets remained safe and pledged to return any amounts it owed.
The company said user funds were “safe” and that “any amounts owed to users will be fully returned.” — Swiss Bitcoin Pay, in its breach disclosure.
That distinction is important because Swiss Bitcoin Pay operates as a non-custodial payment processor. While the suspected breach appears to concern internal systems and customer information, the company has not reported a loss of Bitcoin belonging to customers.
However, the temporary shutdown means merchants using Swiss Bitcoin Pay may be unable to access normal payment-processing services while the investigation continues.
The company has not provided a definite timetable for restoring its servers. Instead, Swiss Bitcoin Pay said its team was working to investigate the breach, strengthen its infrastructure and determine when the platform could safely reopen.
The lack of a confirmed reopening date leaves merchants waiting for further information as the company works through the security incident.
Swiss Bitcoin Pay breach adds to wider crypto security concerns
The Swiss Bitcoin Pay incident comes during a year marked by several data-security incidents involving cryptocurrency companies and related financial platforms.
Reports cited in the original disclosure point to breaches or data leaks involving Revolut, Trezor, Pocket Bitcoin, Bits of Gold and SafePal. Together, the incidents highlight a growing concern within the crypto sector: attackers do not necessarily need direct access to cryptocurrency wallets to create risks for users.
In the Revolut case, the company reportedly disclosed customer information after responding to an email from a malicious actor using a government-agency domain. The information reportedly included home addresses, email addresses, phone numbers, copies of passports or driver’s licenses, verification selfies and IBANs.
The Swiss Bitcoin Pay incident differs in its known scope, but the potential exposure of financial and identifying information creates similar concerns for affected customers.
Data such as an email address paired with a Bitcoin address can provide an attacker with useful information for crafting convincing messages. An exposed IBAN could also increase the risk of fraudulent banking-related communications.
For that reason, customers affected by the Swiss Bitcoin Pay breach and other recent crypto-sector incidents are being urged to remain alert to suspicious communications.
Swiss Bitcoin Pay users face phishing risks
The immediate concern for Swiss Bitcoin Pay customers may extend beyond the platform’s temporary shutdown. If the suspected breach resulted in customer information being obtained, attackers could potentially use those details to impersonate companies, customer-support representatives or financial institutions.
Users should therefore be cautious about unexpected emails, phone calls, messages or letters claiming to relate to their Swiss Bitcoin Pay accounts. Requests for passwords, recovery information, wallet credentials or other sensitive details should receive particular scrutiny.
The company has not said that customer funds were stolen, and its statement specifically indicated that funds remained safe. Nevertheless, users should distinguish between the security of their assets and the privacy of information stored on company systems.
Swiss Bitcoin Pay has also not disclosed the number of customers potentially affected by the incident or confirmed whether every category of information listed in its warning was accessed.
The investigation is therefore expected to determine the extent of the breach, what information was actually exposed and what additional security measures may be required before services resume.
Until the company provides further details, Swiss Bitcoin Pay customers have reason to treat unsolicited communications with caution and verify any request through official channels rather than links or contact information supplied in unexpected messages.
The incident also underscores a broader challenge for crypto businesses: protecting user information can be as important as securing digital assets themselves. As cryptocurrency services expand their merchant and customer bases, breaches involving conventional personal and banking information can create risks that extend well beyond the blockchain.
For now, Swiss Bitcoin Pay remains offline while its team investigates the suspected intrusion. The company has promised to return any amounts owed to users and has yet to announce when its servers will be restored.