ZEUS suffers cyber attack, Lightning Internet Wallet offline audit
The self-hosted Bitcoin Lightning Internet Wallet ZEUS (@ZeusLN) suffered a cyber security incident on Wednesday and subsequently took its infrastructure offline. Founder @evankaloudis said the attack was contained, but the service would remain shut down until the team completed an audit of all systems.
The company released details on the X platform and in a blog post, saying it contained the attack within hours and found no evidence that the incident affected external Lightning Node software. Founder Evan Kaloudis wrote that investigations so far have shown that the incident was limited to ZEUS infrastructure, but did not disclose technical details or a recovery timeline.
ZEUS said its core custody protection mechanism remained intact during the incident. As a precautionary measure, some LSP (Lightning Service Provider) channels have been closed and will be re-enabled after service is restored. No client funds have suffered losses or been at risk.
Part of a wave of lightning network service outages
The ZEUS incident made it the third well-known lightning network service provider to suspend service in approximately 72 hours, after Boltz and AQUA also had outages. The series of service outages have raised concerns about the security of Lightning network infrastructure providers, although analysts stressed that these issues do not reflect vulnerabilities in the Bitcoin Lightning network itself.
Earlier this week, ZEUS disabled the unmanaged bitcoin exchange service Boltz's redemption feature after it ceased operations. Redemption suspensions and cybersecurity incidents are two separate matters, but both limit the functionality of some users.
Looking ahead, ZEUS said it plans to work on the Trusted Execution Environment (also known as Enclave) and the Verification Lightning Signer (VLS) project to strengthen the signature infrastructure and reduce single points of failure.
Tough week for Bitcoin self-custody
When ZEUS came under attack,$BTC holders were already in a difficult week. Starting July 30, 2026, attackers exploited a five-year-old firmware vulnerability in Coinkite's Coldcard hardware wallet to systematically steal Bitcoin from affected devices. The vulnerability dates back to a firmware version in March 2021 and a build configuration error that caused seed generation to fall back to a weak software random number generator rather than the device's hardware entropy source. At least four waves of theft have occurred since then, with Galaxy Research's real-time loss statistics showing that approximately 1,816 $BTC (worth nearly $116 million) were stolen from more than 5,200 addresses.
Coinkite has released the repaired firmware, advising affected users to migrate funds to newly generated, unaffected seeds.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC