Swiss Bitcoin Pay, a non-custodial bitcoin payment processor used by more than 1,000 merchants in 21 countries, went dark on Monday. The company said a malicious user had “likely gained access” to its internal systems and shut its servers down as a precaution while it investigates.
The good news is structural: because Swiss Bitcoin Pay is non-custodial, there was no pile of merchant bitcoin sitting on its servers waiting to be stolen. The bad news is structural too. A payment processor still holds a map of who gets paid, where and how much — and that map may now be in someone else’s hands.
Key facts
- Swiss Bitcoin Pay, a non-custodial bitcoin payment processor based in Neuchâtel, Switzerland, took its servers offline on September 14, 2026 after a suspected intrusion.
- In a statement on X, the company said a malicious user had “likely gained access” to its internal systems.
- Possibly exposed: customer emails, bitcoin addresses, IBANs, transaction history and hashed passwords.
- Swiss Bitcoin Pay says user funds are safe and any amounts owed will be paid in full; no reopening date has been given.
- Bitcoin.com says the processor serves 1,000+ merchants in 21 countries and counts it as at least the sixth crypto company breached in 2026.
What happened at Swiss Bitcoin Pay on September 14?
On September 14, 2026, Swiss Bitcoin Pay said a malicious user had likely gained access to its internal systems and took its servers offline as a precaution. Customer emails, bitcoin addresses, IBANs, transaction history and hashed passwords may have been exposed. The investigation is ongoing, and the company has not said when it will reopen.
Founded in late 2022 in Neuchâtel, Swiss Bitcoin Pay lets merchants accept bitcoin both on-chain and over Lightning. As Bitcoin Magazine reported, the company’s disclosure was short on specifics. Three things are still unknown: whether the data was copied or only viewed, how the attacker got in, and how many accounts are affected.
The wider market shrugged. BTC opened Monday at $76,806 and was trading near $77,873 by 7:31 a.m. ET, with ETH around $2,514, according to Yahoo Finance — where the bigger talking point was an 86.5% probability of a Fed rate hike.
Are Swiss Bitcoin Pay merchants’ funds safe?
According to the company, yes: Swiss Bitcoin Pay says user funds are safe and any amounts owed will be paid in full. That is plausible by design. A non-custodial processor routes payments toward merchants’ own wallets instead of keeping balances for them, so an intruder in its servers doesn’t find a treasury to empty.
The immediate problem is downtime. With the servers off and no reopening date, merchants who relied on Swiss Bitcoin Pay as their only bitcoin checkout currently can’t take payments through it. The second problem is what comes after a breach like this: phishing. A leaked list of verified merchant emails is exactly what scammers need for convincing “reset your password” or “claim your pending payout” messages. If you’re a customer, treat any such email with suspicion, and change the password anywhere you reused it.
Why does leaked payment metadata matter?
Because a bitcoin address linked to an IBAN and an email stops being pseudonymous. Anyone holding that combination can look up the address on a block explorer, estimate a merchant’s revenue and payment patterns, and tie all of it to a real bank account and a real inbox. The coins stay put; the privacy doesn’t.
| Possibly exposed | What it can reveal |
|---|---|
| Email address | Who the merchant is; a ready-made phishing target |
| Bitcoin addresses | Every on-chain payment to those addresses, visible on a block explorer |
| IBAN | The merchant’s real-world bank identity and fiat settlement |
| Transaction history | Volumes, timing and how the business earns |
| Hashed passwords | Risk for weak or reused passwords if hashes are cracked |
This is the same lesson as Revolut handing customer data to a fake government request two days earlier: data a company holds is data that can leak. Bitcoin.com counts Swiss Bitcoin Pay as at least the sixth crypto company breached in 2026, alongside Revolut, Trezor, Pocket Bitcoin, Bits of Gold and SafePal.
Non-custodial protects your coins. It doesn’t protect your metadata.
What should merchants who accept bitcoin do now?
Treat this as a checklist, whichever processor you use:
- Collect only the data you need. Every field you store — or let a vendor store — is one more thing that can leak.
- Use a fresh address per invoice. A reused address lets anyone who learns it add up your revenue from a single leak.
- Keep a backup payment option. If your only processor goes dark, so does your checkout. A second method keeps you selling.
- Settle to a separate wallet. Keep incoming payments apart from your treasury and personal funds, and move them on your own schedule.
- If you’re a Swiss Bitcoin Pay customer: change reused passwords, ignore unsolicited payout or login emails, and wait for official updates from the company.
Where non-custodial payment links fit
SwapZilla Pay takes the same non-custodial approach: payments go to the merchant’s own wallet, and payment links let you bill a customer without building a checkout. We won’t claim it can’t be breached — no hosted service can honestly promise that. The questions worth asking any processor, including us, are the same: does it hold your funds, and how much data does it keep about you? It can also be the backup option on the list above, so one processor going dark doesn’t take your checkout with it. More in our guide to accepting crypto payments non-custodially and the SwapZilla Pay vs BTCPay vs NOWPayments comparison.
Final thoughts
Swiss Bitcoin Pay’s design did the most important job: as far as the company says, there were no customer coins on its servers to take. But a breach doesn’t need to steal bitcoin to hurt merchants. Emails, addresses, IBANs and payment histories are a business’s financial fingerprint, and once copied, they don’t come back.
The safest data is the data nobody collected.
Pick tools that hold as little as possible, keep more than one way to get paid, and assume that anything stored somewhere will eventually be read by someone it wasn’t meant for.