Hacker looking at computer screen with code on it
TECHNOLOGY

ZEUS Takes Infrastructure Offline After Cyberattack

Image credit: Pexels

ZEUS has temporarily taken its infrastructure offline after mitigating a cybersecurity incident reported on August 5. The self-custodial Bitcoin and Lightning wallet said no customer funds were lost or remain at risk.

Services will stay offline while the company audits its systems before restoring operations. ZEUS has not disclosed how the attacker gained access, which infrastructure was affected or when the review will be completed.

Closed Lightning Channels Will be Replaced After Services Resume

Founder Evan Kaloudis said customers whose Lightning Service Provider channels closed during the incident will receive replacement channels once ZEUS restores its services and can process requests.

Affected users have been instructed to contact the support email listed under the Help menu in the ZEUS mobile wallet. The company warned that responses may take longer while its team works through the requests.

ZEUS has not disclosed how many LSP channels were closed or how many users require replacements. Its wallet remains self-custodial, meaning customers control their private keys, but a closed LSP channel can temporarily reduce their access to Lightning liquidity until another channel is opened.

ZEUS Finds no Flaw in Lightning Node Software

ZEUS said its investigation currently indicates that the incident was limited to infrastructure operated by the company. It found no evidence that the attack resulted from a vulnerability in Lightning node software.

The distinction separates the infrastructure compromise from the underlying Bitcoin and Lightning protocols. ZEUS has not identified the attack method, released technical indicators or said whether operational or customer information was accessed.

The company kept its systems offline after mitigating the attack, so its team could conduct a wider audit before resuming services.

New Architecture Will Separate Private Keys From Lightning Nodes

ZEUS said the incident reinforced security work already underway involving trusted execution environments and the Validating Lightning Signer project. Its planned architecture is intended to mitigate similar attacks in the future.

VLS separates Lightning private keys and signing operations from node software. It evaluates signing requests against Lightning protocol rules and configured security policies, rejecting requests that are invalid or outside those limits.

ZEUS has not provided a deployment date for the new architecture. Services will remain unavailable until the company completes its audit and determines that operations can resume, after which it plans to process replacement requests from users whose LSP channels were closed.

More For You

Bitcoin Red Team Flags 4,962 Issues
TECHNOLOGY

Bitcoin Red Team Flags 4,962 Issues

Bitcoin Red Team has flagged 4,962 issues, highlighting potential security, code quality and operational…

Aug 6, 2026 2 min read
Explore More News