JAN3 has temporarily paused forward swaps on Indra after a denial-of-service attack struck the service within hours of its open beta launch on September 15, 2026. CEO Samson Mow said swaps already in progress could take longer to complete while the team investigates and prepares further updates.

The disruption hit JAN3’s own swap infrastructure rather than Bitcoin or the Lightning Network protocols. Based on the information released so far, there is no indication of a protocol-level failure, but the incident has again drawn attention to the operational risks around the service providers built on top of Lightning.

Attack follows launch of new swap system

Indra is JAN3’s custom swap infrastructure for moving Bitcoin between the Lightning and Liquid networks. It was introduced by AQUA Wallet as an in-house replacement for Boltz, which JAN3 had previously relied on for that function.

According to the company’s initial account, the attack landed only hours after the open beta went live. JAN3 then disabled forward swaps as it worked to assess the impact and stabilize the service.

Delays expected for swaps already underway

Mow said users with swaps already in flight may see delays in completion. JAN3 has not yet provided a full timeline for restoring forward swaps, and said more information would follow as the investigation continues.

The company also indicated that Liquid pegging activity was being restored, although liquidity limits still apply during operations. That suggests some parts of the broader system were returning while the affected swap flow remained restricted.

Part of a wider pattern of provider disruptions

The Indra incident comes amid a broader run of outages affecting service providers tied to Lightning-based activity. Boltz, AQUA and ZEUS have all paused operations around similar periods, although there is no evidence in the available reporting that these events were connected beyond their timing.

At the same time, the underlying Lightning Network appears to have remained largely stable. Open Lightning nodes and overall network capacity were reported as resilient despite failures or interruptions at specific providers.

Service infrastructure is under closer scrutiny

The attack highlights a recurring distinction in crypto payments infrastructure: failures can occur at the provider layer even when the underlying protocol continues to function. In this case, the target was a provider-run swap service, not Bitcoin itself and not the Lightning protocol.

That separation matters because more consumer-facing products now depend on service operators to handle routing, swaps and liquidity management. As those services become more widely used, denial-of-service attacks and other operational outages can become a bigger obstacle to reliability and adoption.

What comes next for Indra

For now, the main confirmed next step is further communication from JAN3 on the status of the attack and the restoration of forward swaps. The immediate points to watch are how long the pause lasts, whether pending swaps clear without further disruption, and what changes JAN3 makes as Indra moves beyond its open beta stage.

Source: Cryptopolitan