Swiss Bitcoin Pay breach: servers offline, merchant data possibly exposed

On September 14, 2026, non-custodial processor Swiss Bitcoin Pay took its servers offline after an intruder likely accessed internal systems. Emails, bitcoin addresses and IBANs may be exposed; it says funds are safe.

Voxel shield in red with a white Swiss-style cross, cracked, with debris cubes on a dark background

Swiss Bitcoin Pay, a non-custodial bitcoin payment processor used by more than 1,000 merchants in 21 countries, went dark on Monday. The company said a malicious user had “likely gained access” to its internal systems and shut its servers down as a precaution while it investigates.

The good news is structural: because Swiss Bitcoin Pay is non-custodial, there was no pile of merchant bitcoin sitting on its servers waiting to be stolen. The bad news is structural too. A payment processor still holds a map of who gets paid, where and how much — and that map may now be in someone else’s hands.

Key facts

  • Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, took its servers offline on September 14, 2026 after a suspected intrusion.
  • In a statement on X, the company said a malicious user had “likely gained access” to its internal systems.
  • Possibly exposed: customer emails, bitcoin addresses, IBANs, transaction history and hashed passwords.
  • Swiss Bitcoin Pay says user funds are safe and any amounts owed will be paid in full; no reopening date has been given.
  • Bitcoin.com says the processor serves 1,000+ merchants in 21 countries and counts it as at least the sixth crypto company breached in 2026.

What happened at Swiss Bitcoin Pay on September 14?

On September 14, 2026, Swiss Bitcoin Pay said a malicious user had likely gained access to its internal systems and took its servers offline as a precaution. Customer emails, bitcoin addresses, IBANs, transaction history and hashed passwords may have been exposed. The investigation is ongoing, and the company has not said when it will reopen.

Founded in late 2022 in Neuchâtel, Swiss Bitcoin Pay lets merchants accept bitcoin both on-chain and over Lightning. As Bitcoin Magazine reported, the company’s disclosure was short on specifics. Three things are still unknown: whether the data was copied or only viewed, how the attacker got in, and how many accounts are affected.

The wider market shrugged. BTC opened Monday at $76,806 and was trading near $77,873 by 7:31 a.m. ET, with ETH around $2,514, according to Yahoo Finance — where the bigger talking point was an 86.5% probability of a Fed rate hike.

Are Swiss Bitcoin Pay merchants’ funds safe?

According to the company, yes: Swiss Bitcoin Pay says user funds are safe and any amounts owed will be paid in full. That is plausible by design. A non-custodial processor routes payments toward merchants’ own wallets instead of keeping balances for them, so an intruder in its servers doesn’t find a treasury to empty.

The immediate problem is downtime. With the servers off and no reopening date, merchants who relied on Swiss Bitcoin Pay as their only bitcoin checkout currently can’t take payments through it. The second problem is what comes after a breach like this: phishing. A leaked list of verified merchant emails is exactly what scammers need for convincing “reset your password” or “claim your pending payout” messages. If you’re a customer, treat any such email with suspicion, and change the password anywhere you reused it.

Why does leaked payment metadata matter?

Because a bitcoin address linked to an IBAN and an email stops being pseudonymous. Anyone holding that combination can look up the address on a block explorer, estimate a merchant’s revenue and payment patterns, and tie all of it to a real bank account and a real inbox. The coins stay put; the privacy doesn’t.

Possibly exposedWhat it can reveal
Email addressWho the merchant is; a ready-made phishing target
Bitcoin addressesEvery on-chain payment to those addresses, visible on a block explorer
IBANThe merchant’s real-world bank identity and fiat settlement
Transaction historyVolumes, timing and how the business earns
Hashed passwordsRisk for weak or reused passwords if hashes are cracked

This is the same lesson as Revolut handing customer data to a fake government request two days earlier: data a company holds is data that can leak. Bitcoin.com counts Swiss Bitcoin Pay as at least the sixth crypto company breached in 2026, alongside Revolut, Trezor, Pocket Bitcoin, Bits of Gold and SafePal.

Non-custodial protects your coins. It doesn’t protect your metadata.

What should merchants who accept bitcoin do now?

Treat this as a checklist, whichever processor you use:

  • Collect only the data you need. Every field you store — or let a vendor store — is one more thing that can leak.
  • Use a fresh address per invoice. A reused address lets anyone who learns it add up your revenue from a single leak.
  • Keep a backup payment option. If your only processor goes dark, so does your checkout. A second method keeps you selling.
  • Settle to a separate wallet. Keep incoming payments apart from your treasury and personal funds, and move them on your own schedule.
  • If you’re a Swiss Bitcoin Pay customer: change reused passwords, ignore unsolicited payout or login emails, and wait for official updates from the company.

SwapZilla Pay takes the same non-custodial approach: payments go to the merchant’s own wallet, and payment links let you bill a customer without building a checkout. We won’t claim it can’t be breached — no hosted service can honestly promise that. The questions worth asking any processor, including us, are the same: does it hold your funds, and how much data does it keep about you? It can also be the backup option on the list above, so one processor going dark doesn’t take your checkout with it. More in our guide to accepting crypto payments non-custodially and the SwapZilla Pay vs BTCPay vs NOWPayments comparison.

Final thoughts

Swiss Bitcoin Pay’s design did the most important job: as far as the company says, there were no customer coins on its servers to take. But a breach doesn’t need to steal bitcoin to hurt merchants. Emails, addresses, IBANs and payment histories are a business’s financial fingerprint, and once copied, they don’t come back.

The safest data is the data nobody collected.

Pick tools that hold as little as possible, keep more than one way to get paid, and assume that anything stored somewhere will eventually be read by someone it wasn’t meant for.

FAQ

What happened to Swiss Bitcoin Pay?
On September 14, 2026, Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, said a malicious user had likely gained access to its internal systems. It shut down its servers as a precaution while investigating and has not given a reopening date. The company serves more than 1,000 merchants in 21 countries, according to Bitcoin.com.
What data was exposed in the Swiss Bitcoin Pay breach?
Swiss Bitcoin Pay said customer emails, bitcoin addresses, IBANs, transaction history and hashed passwords may have been exposed in the September 2026 incident. As of September 14, 2026, it was not known whether the data was copied or only viewed, how the attacker got in, or how many accounts were affected. Customers should expect phishing attempts using this information.
Are funds safe with Swiss Bitcoin Pay after the breach?
Swiss Bitcoin Pay says user funds are safe and that any amounts owed will be paid in full. Because it is a non-custodial processor, payments go toward merchants’ own wallets rather than sitting on its servers. The practical issue as of September 14, 2026 is downtime: its servers are offline with no reopening date, so merchants cannot take payments through it for now.
What should Swiss Bitcoin Pay merchants do now?
Merchants affected by the September 2026 Swiss Bitcoin Pay breach should change any password they reused elsewhere, ignore unsolicited emails about logins or payouts, and wait for official updates from the company. They should also set up a backup way to accept bitcoin so checkout keeps working, and consider moving to a fresh address per invoice and a separate settlement wallet.
How can merchants accept bitcoin with less data exposure?
Merchants can limit exposure by collecting only the data they need, generating a fresh bitcoin address for each invoice, settling to a separate wallet, and choosing non-custodial processors that hold no balances. The Swiss Bitcoin Pay breach in September 2026 shows why: linking addresses to emails and IBANs lets anyone with the leaked data estimate a merchant’s revenue from the blockchain.