Ugh. Bad news keeps coming for the cryptocurrency world.
ZEUS, the company behind the popular self-custodial Bitcoin Lightning wallet, has taken its infrastructure offline after suffering a cybersecurity incident. While the company says no customer funds were lost or placed at risk, the attack was serious enough that it is keeping services offline until a comprehensive security audit is complete.
In a security update published today, ZEUS said it has already mitigated the attack but is delaying restoration of services “out of an abundance of caution.” The company has not disclosed how the attackers gained access or what systems were affected.
Importantly, ZEUS says its investigation has found no evidence that the incident was caused by a vulnerability in Lightning node software. Instead, the company currently believes the compromise was limited to its own infrastructure.
Some users have still been affected. ZEUS confirmed that Lightning Service Provider (LSP) channels were closed as part of the incident. Those customers will receive replacement channels after services return and the company is able to process requests.
“No customer funds were lost. No customer funds are at risk,” ZEUS wrote in its update, attempting to reassure users who may have been alarmed by the unexpected outage.
The company also pointed to security improvements already in development, including the use of trusted execution environments, often called enclaves, and the Validating Lightning Signer project. According to ZEUS, its upcoming architecture is specifically designed to reduce the impact of this type of attack.
Although there is no indication this incident is related, it arrives just as the cryptocurrency industry is dealing with another high-profile security story. Earlier this week, thousands of older Coldcard hardware wallets were reportedly compromised after attackers regenerated predictable wallet seeds created by a flawed 2021 firmware build. Unlike the ZEUS incident, which the company says did not put customer funds at risk, the Coldcard situation allegedly resulted in the theft of a substantial amount of Bitcoin.
The two incidents appear to be entirely unrelated and involve very different attack scenarios. Still, taken together, they serve as another reminder that cryptocurrency security depends on much more than keeping private keys offline. Infrastructure, software, firmware, and operational security all matter, and weaknesses in any one of those areas can have serious consequences.
ZEUS has not provided a timeline for restoring services, saying only that operations will resume after its security review is complete. In the meantime, affected users are being asked to contact support through the Help menu in the ZEUS mobile wallet if their LSP channels were closed.
As more details emerge, it will be interesting to learn exactly how the attackers breached ZEUS’s infrastructure and whether any additional safeguards could have prevented the incident in the first place. For now, users at least have one piece of good news: according to the company, their Bitcoin remains safe.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz