Zeus Wallet takes offline infrastructure after defusing cybersecurity incident
Zeus Wallet has taken offline its infrastructure after defusing a cybersecurity incident. The company said no customer funds were lost or at risk until a comprehensive systems audit was completed and services were restored.
Incident Summary
Zeus Wallet has taken its infrastructure offline after defusing a cybersecurity incident. The company said no customer funds suffered losses and no vulnerabilities in Lightning Node software were found. Users who use Lightning Service Provider (LSP) channels and the channel is closed will receive a replacement channel after service is restored. Zeus is conducting an audit of the system before resuming operations and has not provided a specific timetable. The incident comes as Bitcoin developers step up security reviews due to recent Coldcard wallet attacks.
Zeus Wallet announced the incident in an update on August 5, saying the attack was contained within hours, but the infrastructure will remain offline until a comprehensive review of its systems is completed. The self-hosted Bitcoin Lightning Internet Wallet said its investigation has so far found no evidence that the incident originated from a vulnerability in Lightning Node software. Founder Evan Kaloudis said in a company blog that investigators currently believe the attack was limited to Zeus 'own infrastructure. He added that the company had not found any impact on customer funds and would continue to audit its systems before resuming services online. No specific timetable for resuming operations has been provided.
Zeus says client funds are safe
While infrastructure remains unavailable, Zeus said customers whose Lightning Service Provider (LSP) channels were closed during the incident will receive replacement channels after service is restored and requests are processed. The company also asked affected users to contact the support team through the help section of Zeus Mobile Wallet, while warning that response times could be longer than usual due to increased support requests during the outage. Kaloudis said the incident strengthens the ongoing work of Zeus and the Validating Lightning Signer (VLS) project on a trusted execution environment, also known as an enclosure. According to the company, the planned infrastructure design is designed to mitigate such attacks.
Although Zeus described the incident as a cybersecurity attack, it did not disclose how the attacker gained access or whether any internal systems outside its infrastructure were affected.
Previously, the service outage followed Boltz's shutdown
The infrastructure outage occurred only days after Zeus announced another service change that affected users. On Monday, the wallet said it would disable the exchange feature after unmanaged bitcoin exchange service provider Boltz suspended its platform indefinitely. Zeus linked the decision directly to Boltz's shutdown, although the exchange suspension and cybersecurity incidents were announced separately. The company did not say the two incidents were related. Currently, Zeus 'top priority remains to complete internal audits, then restore infrastructure and process replacement lightning channels for affected customers.
Bitcoin security review accelerates after Coldcard attack
The Zeus incident comes at a time when security reviews of the Bitcoin ecosystem have intensified following the recent Coldcard wallet attack. Earlier this week, Bitcoin developer Calle said that the bitcoin red team led by volunteers had begun reviewing Bitcoin wallets, libraries, infrastructure software and other open source projects, using artificial intelligence-assisted analysis combined with manual verification. Based on data shared by the team, reviewers inspected 390 bitcoin-related code warehouses in the first 29.8 hours after the project was launched and identified 4,962 potential security issues. The team classified 720 findings as high or severe, while reporting that 21.4% of the identified issues had been replicated through subsequent verification. Calle said several key vulnerabilities had been privately disclosed to affected project maintainers rather than publicly released to prepare software fixes. This volunteer effort includes AnchorWatch CEO Rob Hamilton and other Bitcoin contributors. Calle also said the program consumes approximately $10,000 in computing costs per day, is funded by OpenSats, and Kimi Moonshot provides access to the AI account and its Kimi K3 model.
Coldcard survey continues, affected users migrate wallets
Security reviews have been stepped up after investigators linked the recent Bitcoin theft to flaws in certain Coldcard hardware wallet firmware versions. Galaxy Research confirmed that the attacker stole 1,596 BTC from approximately 7,300 addresses in three confirmed attack waves. The research company also identified a suspected fourth coordinated attack wave involving an additional 448.7 BTC from 709 suspected victim addresses, but has not yet added these losses to its confirmation data because additional victim verification is still ongoing. Investigators separately reported that about 90% of stolen bitcoins have not yet been moved on the chain. At the same time, analysts observed that one attacker routed 64 BTC through a Bitcoin mixer, while the largest identified attacker still held approximately 1,159 BTC in seven addresses. According to hardware wallet maker Coinkite, the potential Coldcard vulnerability stems from firmware modifications introduced in March 2021 when integrating the new cryptographic library. During the wallet creation process, the affected firmware versions did not rely on the expected hardware random number generator, but instead used the deterministic pseudo-random generator provided by MicroPython. Block's Bitcoin engineering and security team came to the same conclusion after an independent review of the firmware. Although the company said it had not completed empirical testing on all affected devices, its analysis found that vulnerable firmware relied on deterministic fallback during seed generation rather than the STM32 hardware random number generator. Coinkite has since released emergency firmware updates for affected devices, but warned that simply installing patched software will not protect wallets created using vulnerable firmware. Users were instructed to generate brand new seed phrases on their updated devices and transfer their bitcoins to addresses derived from these new wallets. The company added that wallets originally created using at least 50 private dice rolls were not affected by this specific random number generation flaw, but still recommended migrating to newly generated seeds.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC