Swiss Bitcoin Pay is currently offline as the company investigates a significant data breach that exposed sensitive user information, including Bitcoin addresses and hashed passwords. While the platform’s non-custodial nature ensures that user funds were not stolen—as the company never holds private keys—the exposure of IBANs and transaction histories poses a substantial privacy risk. The Neuchâtel, Switzerland-based processor took its servers down on Monday to mitigate the damage and begin a full security audit.
The breach involved the exfiltration of customer metadata that could link real-world identities to specific Bitcoin transactions. The company reported that while passwords were encrypted (hashed), the combination of email addresses and transaction history makes users vulnerable to highly targeted phishing campaigns and physical security threats. Swiss Bitcoin Pay has urged its users to remain vigilant against suspicious communications claiming to be from their support team.
This incident arrives at a time when Swiss crypto firms are under increased scrutiny regarding the Federal Act on Data Protection (FADP). Even though Switzerland is considered a premier hub for digital asset innovation, this breach highlights the vulnerability of the infrastructure surrounding the Bitcoin network. For US-based users and international merchants who rely on Swiss processors for their regulatory clarity, the shutdown serves as a reminder that non-custodial services still carry significant operational risks regarding metadata.
Moving forward, investors and users should watch for the company's official post-mortem report and the restoration of its API services. The market will also be observing whether Swiss regulators impose fines or new security mandates on payment processors following this leak. For now, users who have interacted with the service are advised to treat their associated Bitcoin addresses as potentially linked to their personal identity and to monitor their linked bank accounts for any unusual activity.