Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, temporarily disabled its servers on Monday following a data breach. The company stated that while user funds remained safe, a malicious actor likely accessed internal systems containing customer email addresses, bitcoin addresses, IBANs, transaction history, and hashed passwords. The firm assured users that any amounts owed would be fully returned and is currently investigating to secure its infrastructure.
This incident occurs amidst a series of security failures affecting fintech and crypto firms in 2026. Recent breaches include Revolut handing over sensitive identity documents to an unauthorized party via fraudulent government-domain requests, SafePal exposing order information for approximately 39,798 customers, and scammers accessing Ledger customer data through payment processor Global-e. Swiss Bitcoin Pay facilitates business payments via on-chain transactions and the Lightning Network but did not immediately respond to further comment requests.
The shutdown highlights the operational fragility inherent in non-custodial payment infrastructure, where the protection of private keys does not necessarily safeguard associated metadata or communication channels. While Swiss Bitcoin Pay emphasized that direct fund access was prevented, the exposure of IBANs and transaction histories creates significant secondary risks for users, including targeted phishing and social engineering attacks that can compromise wallet security indirectly.
From an Operational Risk perspective, this event underscores a broader trend of attackers exploiting third-party integrations and internal system vulnerabilities rather than blockchain protocols themselves. The clustering of incidents involving major players like Revolut, Ledger, and SafePal suggests that traditional cybersecurity measures are struggling to keep pace with sophisticated social engineering tactics. Stakeholders should monitor how quickly Swiss Bitcoin Pay restores services and whether it implements enhanced verification protocols to mitigate the fallout from leaked personal identifiers.


