Friday, August 7, 2026

Zeus Lightning Wallet Offline Following Infrastructure Cyberattack

Futuristic header illustrating a crypto wallet cyberattack with neon blue and purple glow and infrastructure isolation.

ZEUS took core infrastructure offline on August 5 after detecting and mitigating a cybersecurity incident, triggering a precautionary audit of its systems. The self-custodial Bitcoin and Lightning wallet said no customer funds were lost or considered at risk, while its preliminary investigation found no evidence that a vulnerability in Lightning node software caused the breach.

The shutdown affected supporting services rather than producing a confirmed compromise of the Lightning protocol itself. ZEUS has not disclosed the attack vector or identified which internal systems were accessed. That leaves the incident contained but only partially explained, with the company continuing its investigation before restoring every affected component.

Service Restoration Has Already Begun

The outage is no longer a complete shutdown. In an August 6 update, ZEUS said its Pay Lightning Addresses had returned online, while ZEUS White, block-source and graph-data services remained operational throughout the incident. Currency exchange-rate services experienced brief disruption and were subsequently stabilized. Lightning node and Lightning Service Provider channel services are still scheduled to return in the coming days.

Customers whose LSP channels were closed during the incident will receive replacement channels once ZEUS can process those requests. The company has directed affected users to contact support through the wallet’s Help menu. The remediation addresses lost channel connectivity rather than reimbursing stolen balances, because ZEUS says no customer funds were taken.

ZEUS’s self-custodial model is relevant, but the company has not publicly established that self-custody alone prevented financial loss. Its open-source wallet is designed to let users manage Bitcoin and Lightning without handing the company conventional custody of their private keys. The incident shows that supporting infrastructure can fail even when asset custody remains separated, potentially disrupting channels and services without necessarily compromising user balances.

Security Roadmap Focuses on Separating Signing Authority

Founder Evan Kaloudis said the attack reinforces work already underway around trusted execution environments and Validating Lightning Signer, or VLS. VLS is designed to keep Lightning private keys away from the node and validate requests before signing them. Separating signing authority from operational infrastructure can limit what an attacker can do after compromising a node or server, although ZEUS’s planned architecture is not yet evidence that future attacks will be prevented.

The incident followed a separate service interruption on August 3, when ZEUS disabled its Boltz-backed swap instance after Boltz suspended swap services indefinitely. Boltz said its API remained available for cooperative refunds and that unilateral refunds did not depend on its infrastructure. ZEUS has not linked the Boltz disruption to the August 5 cyberattack, so the two events should be treated separately.

The outstanding questions are the original attack method, the scope of the compromised infrastructure and the completion of the security audit. The most important confirmed outcome remains that ZEUS reports no customer losses while service restoration is progressing in stages, with Lightning node and LSP operations still awaiting full recovery.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.