Swiss Bitcoin Pay, a non-custodial Bitcoin payment processor based in Neuchâtel, has taken its entire server infrastructure offline after detecting what it described as likely unauthorized access to its internal systems. The shutdown began on September 14 and no reopening date has been announced.

The incident was first reported by Crypto Briefing and has since been corroborated by Coinpedia, Odaily and other outlets. The company has not named a suspected attacker, disclosed an entry vector, or said how many customers' records may be involved.

What May Have Been Exposed

According to the company's own account, relayed consistently across outlets, the intruder may have reached five categories of data:

  • Email addresses
  • Bitcoin wallet addresses
  • IBAN bank account numbers
  • Transaction histories
  • Hashed passwords

Hashed passwords are not plaintext, but weaker hashes can be cracked offline given enough compute — which is why the company has not ruled out further account risk. As of publication, Swiss Bitcoin Pay has not confirmed whether data was actually copied off its systems or merely accessible to the intruder, a distinction that will matter both for customers and for the Swiss regulator.

Why Funds Appear Safe

Swiss Bitcoin Pay operates a non-custodial model: when a customer pays a merchant through the platform, funds route directly to the merchant's own wallet rather than resting in an account controlled by the processor. The company says customer funds and private keys are unaffected by the incident — a claim consistent with that architecture, since there should be no pooled custody to breach.

The blast radius, in other words, is data, not coins. But the data in question is precisely the dangerous kind. Email addresses paired with Bitcoin addresses, IBANs and transaction histories reconstruct the same linkage that made the Revolut disclosure a security problem rather than a privacy footnote: verified identity connected to visible on-chain activity. Expect the exposed records to fuel targeted phishing — payment-processor impersonation, fake "security updates," invoice fraud — aimed at the platform's merchants and their customers.

The Swiss Context

Swiss Bitcoin Pay is registered as a financial intermediary under Swiss anti-money-laundering law, which brings reporting obligations toward regulators, and the country's data protection rules require notifying affected customers when a breach creates meaningful privacy risk. How quickly the company fills in the missing details — scale, vector, whether data was exfiltrated — will now determine the regulatory and reputational tail of the incident.

The disclosure lands during a rough stretch for Swiss crypto infrastructure: three days earlier, Bitcoin Suisse announced it would cut up to 60 of its roughly 120 Swiss staff as part of a restructuring. The two stories are unrelated, but together they put an uncomfortable spotlight on a jurisdiction that markets itself as crypto's most trusted home.

What Users Should Do

For merchants and customers of the service, the guidance is the same as in every breach of this shape. Treat any email claiming to be from Swiss Bitcoin Pay — especially one referencing recent transactions or asking for password changes, wallet details or payment re-routing — as suspect until verified through the company's official website once service resumes. Change the platform password when the service comes back online, and reuse that password nowhere else.

The incident is also the third email-adjacent data exposure to hit European crypto users inside two weeks, after the Trezor and BitBox newsletter breach and the Brevo SSO flaw that grew out of it. Attackers are clearly working the same seam: the marketing and back-office software around crypto companies, not the cryptography itself.

TrustGrade tracks the security posture of payment processors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.