
Zeus Wallet has taken its infrastructure offline after mitigating a cybersecurity incident, saying no customer funds have been lost or placed at risk while it completes a full systems audit before restoring services.
Summary
- Zeus Wallet has taken its infrastructure offline after mitigating a cybersecurity incident.
- The company said no customer funds were lost and no Lightning node software vulnerability has been identified.
- Users with closed Lightning Service Provider channels will receive replacement channels after services resume.
- Zeus is auditing its systems before restoring operations and has not provided a timeline.
- The incident comes as Bitcoin developers expand security reviews following the recent Coldcard wallet attacks.
Zeus Wallet announced the incident in an Aug. 5 update, saying the attack had been contained within hours but that infrastructure would remain offline until a comprehensive review of its systems is completed. The self-custodial Bitcoin Lightning Network wallet said its investigation has so far found no evidence that the incident stemmed from a vulnerability in Lightning node software.
Founder Evan Kaloudis said in a company blog post that investigators currently believe the attack was limited to Zeus’ own infrastructure. He added that the company has not identified any impact on customer funds and is continuing to audit its systems before bringing services back online.
No timeline has been provided for restoring operations.
Zeus says customer funds remain safe
While infrastructure remains unavailable, Zeus said customers whose Lightning Service Provider (LSP) channels were closed during the incident will receive replacement channels once services resume and requests can be processed.
The company also asked affected users to contact support through the help section of the Zeus mobile wallet, while warning that response times may be longer than usual as support requests increase during the outage.
Kaloudis said the incident has reinforced Zeus’ ongoing work on trusted execution environments, also known as enclaves, together with the Validating Lightning Signer (VLS) project. According to the company, the planned infrastructure design is intended to mitigate this category of attack.
Although Zeus described the incident as a cybersecurity attack, it did not disclose how the attackers gained access or whether any internal systems outside its infrastructure were affected.
Previous service disruption followed Boltz shutdown
The infrastructure outage comes only days after Zeus announced another service change affecting users.
On Monday, the wallet said it would disable swap functionality after non-custodial Bitcoin swap provider Boltz suspended its own platform until further notice. Zeus linked the decision directly to Boltz’s shutdown, although the swap suspension and the cybersecurity incident have been announced separately.
The company has not indicated that the two events are connected.
For now, Zeus’ current priority remains completing its internal audit before restoring infrastructure and processing replacement Lightning channels for affected customers.
Bitcoin security reviews have accelerated after Coldcard attacks
The Zeus incident arrives during a period of heightened security reviews across the Bitcoin ecosystem following the recent Coldcard wallet attacks.
Earlier this week, Bitcoin developer Calle said the volunteer-led Bitcoin Red Team had begun reviewing Bitcoin wallets, libraries, infrastructure software and other open-source projects using AI-assisted analysis combined with manual verification after the Coldcard incident.
According to data shared by the group, reviewers examined 390 Bitcoin-related repositories during the first 29.8 hours of the initiative, identifying 4,962 potential security issues. The team classified 720 findings as high or critical severity, while reporting that 21.4% of identified issues had already been reproduced through follow-up verification.
Calle said several critical vulnerabilities had already been privately disclosed to affected project maintainers rather than released publicly while software fixes are being prepared.
The volunteer effort includes AnchorWatch CEO Rob Hamilton and other Bitcoin contributors. Calle also said the initiative is consuming about $10,000 per day in computing costs, with OpenSats funding the effort and Kimi Moonshot providing AI accounts and access to its Kimi K3 model.
Coldcard investigation continues as affected users migrate wallets
Security reviews intensified after investigators linked recent Bitcoin thefts to a flaw in certain Coldcard hardware wallet firmware versions.
As previously reported by crypto.news, Galaxy Research confirmed that attackers stole 1,596 BTC from roughly 7,300 addresses across three confirmed attack waves. The research firm has also identified a suspected fourth coordinated wave involving another 448.7 BTC from 709 likely victim addresses, although it has not yet added those losses to its confirmed figures because additional victim verification remains ongoing.
Investigators have separately reported that roughly 90% of the stolen Bitcoin has not moved on-chain. At the same time, analysts observed one attacker routing 64 BTC through a Bitcoin mixer, while the largest identified attacker continues holding about 1,159 BTC across seven addresses.
According to hardware wallet maker Coinkite, the underlying Coldcard vulnerability originated from a firmware modification introduced in March 2021 while integrating a new cryptographic library. Instead of relying on the intended hardware random-number generator during wallet creation, affected firmware versions used a deterministic pseudo-random generator supplied by MicroPython.
Block’s Bitcoin engineering and security team reached the same conclusion after independently reviewing the firmware. Although the company said it had not completed empirical testing across every affected device, its analysis found that vulnerable firmware relied on the deterministic fallback during seed generation instead of the STM32 hardware random-number generator.
Coinkite has since released emergency firmware updates for affected devices but warned that installing patched software alone does not protect wallets created with vulnerable firmware. Users have instead been instructed to generate completely new seed phrases on updated devices and transfer their Bitcoin to addresses derived from those new wallets.
The company added that wallets originally created using at least 50 private dice rolls are not affected by this specific random-number-generation flaw, though it continues recommending migration to newly generated seeds.





Be the first to comment