Swiss Bitcoin Pay shut down all of its server infrastructure on Monday after determining that an intruder had likely gained access to internal systems. The company described the move as precautionary while it investigates the incident and has not said when services may return.
The firm warned that customer email addresses, Bitcoin addresses, bank IBANs, transaction histories and hashed passwords may have been exposed. It has not confirmed whether any data was actually exfiltrated or only viewed, and it has not disclosed how many customers may have been affected.
What the company says may be at risk
According to Swiss Bitcoin Pay, the suspected breach may have exposed several categories of customer information tied to account activity and payments. The company specifically listed email addresses, Bitcoin addresses, IBANs, transaction histories and hashed passwords among the data that could have been accessible to the intruder.
So far, the company has not explained how the attacker may have entered its systems. It also has not linked the incident to any specific vulnerability or stated whether the data was copied, altered or simply observed during the intrusion.
Why customer funds were not directly exposed
Swiss Bitcoin Pay said no unauthorized Bitcoin movements have been identified. It attributed that protection to its non-custodial setup, in which payments move directly between the customer and the merchant rather than being held in the company’s main infrastructure.
That said, the company noted that it does briefly hold some user balances in one part of its service flow. Incoming Lightning payments are batched for on-chain output on a daily, weekly or monthly cycle, meaning some amounts can remain with the platform for a limited period before being forwarded.
Main concern shifts to privacy and phishing risks
Even without confirmed theft of Bitcoin, the possible exposure of customer records creates other risks. Information such as email addresses, transaction histories and bank details can be used in targeted phishing attempts aimed at persuading users to reveal more sensitive information or send funds elsewhere.
Bitcoin addresses linked to identifiable customer data can also make transaction tracing easier. In practice, that can reduce user privacy by allowing on-chain activity to be connected to real-world identities more readily than before.
No restoration timeline yet
Swiss Bitcoin Pay has not provided a timetable for bringing its systems back online. For now, the confirmed next step is the company’s ongoing investigation into the suspected internal breach and the scope of any exposure.
The firm said customer funds are not at risk and added that any amounts owed to users would be refunded in full. Until the review is complete, key unknowns remain, including the attack path, the number of affected customers and whether any data was ultimately taken.
Source: Cryptopolitan