On 14 September 2026, Swiss Bitcoin Pay takes its servers down. A malicious user “likely” reached internal systems, the company writes. Precaution. No reopening date.

The Neuchâtel firm lets merchants take bitcoin, on-chain and on Lightning. It says it does not hold merchants’ keys. Customer funds, it says, did not move. “Any amounts owed to users will be fully returned.”

What may have leaked

At this stage the team believes the intruder saw: customer emails, bitcoin addresses, IBANs, transaction history, hashed passwords. It does not know if anything else was taken. This is not an audit list. It is what it published the same day.

Hashed passwords are not passwords in the clear. They remain fuel for phishing. Same pattern as Revolut: the data leaves, the scam arrives later by mail.

No keys held, with a float

Hours later a customer asks: if you do not hold keys, why talk about funds to return? The firm answers. Lightning payments are batched automatically, daily, weekly or monthly, into one on-chain output. During that batch, some money sits with the company. “Generally, these are not significant amounts.”

Merchants’ keys, in the advertised model, are not at Swiss Bitcoin Pay. Lightning batches are. That is the nuance. Not proof that balances were stolen. Proof that “no keys held” does not mean zero bitcoin on the servers.

What is not established

No post-mortem. No count of customers hit. No time of intrusion. Pocket Bitcoin, another Swiss name, already had a data exposure in August. Trezor flagged an email vendor. Nothing says it is the same attacker. Nothing says it is not.

As of 15 September: servers down, funds “safe” according to the issuer, personal data likely seen, no calendar for a return. Treat any “Swiss Bitcoin Pay” mail as suspect until further notice.