Zeus Wallet has taken its infrastructure offline after containing a cybersecurity incident, with the self-custodial Bitcoin Lightning Network wallet saying it has found no evidence that customer funds were lost or put at risk.
The company said the attack was contained within hours, but services will remain unavailable while it carries out a comprehensive audit of its systems. Zeus has not given a timeframe for restoring operations.
In an update published on 5 August, Zeus said its investigation had so far found no indication that the incident was caused by a vulnerability in Lightning node software.
Founder Evan Kaloudis said investigators currently believe the attack was confined to Zeus’ own infrastructure. He added that the company had identified no impact on customer funds and would continue examining its systems before bringing them back online.
Zeus has not disclosed how the attackers gained access, nor whether systems outside its infrastructure were affected.
Customers whose Lightning Service Provider (LSP) channels were closed during the incident will be offered replacement channels after services resume and the company is able to process requests.
Affected users have been asked to contact Zeus through the help section of the mobile wallet. However, the company warned that replies could take longer than normal because of an expected rise in support requests during the outage.
Kaloudis said the incident had underlined Zeus’ continuing work on trusted execution environments, or enclaves, alongside the Validating Lightning Signer (VLS) project. Zeus said the infrastructure design it is developing is intended to reduce the risk of this type of attack.
The outage follows another recent change to services offered by the wallet.
On Monday, Zeus said it would disable its swap functionality after non-custodial Bitcoin swap provider Boltz suspended its platform until further notice. Zeus linked that decision to Boltz’s closure, but announced the swap suspension and the cybersecurity incident separately.
The company has given no indication that the two developments are connected.
For now, Zeus’ stated priority is to complete its internal audit, restore its infrastructure and process replacement Lightning channels for customers affected by the outage.
The incident comes as security checks across the Bitcoin ecosystem intensify following a series of attacks involving Coldcard wallets.
Earlier this week, Bitcoin developer Calle said the volunteer-led Bitcoin Red Team had begun examining Bitcoin wallets, libraries, infrastructure software and other open-source projects. The group is using AI-assisted analysis alongside manual verification after the Coldcard incidents.
The team said it had reviewed 390 Bitcoin-related repositories during the first 29.8 hours of the project, identifying 4,962 potential security issues. Of those, 720 were classified as high or critical severity, while 21.4% of all findings had already been reproduced through further checks.
Calle said several critical vulnerabilities had been disclosed privately to the maintainers of affected projects. The details have not been made public while developers prepare software fixes.
The volunteer operation includes AnchorWatch chief executive Rob Hamilton and other Bitcoin contributors. Calle said it was costing about $10,000 a day in computing resources. OpenSats is funding the project, while Kimi Moonshot is supplying AI accounts and access to its Kimi K3 model.
Security scrutiny increased after investigators linked recent Bitcoin thefts to a weakness in particular versions of Coldcard hardware-wallet firmware.
Galaxy Research confirmed that attackers had stolen 1,596 BTC from about 7,300 addresses in three confirmed attack waves. The research firm has also identified a suspected fourth coordinated wave involving a further 448.7 BTC from 709 likely victim addresses. Those losses have not yet been included in its confirmed total because further verification of victims is still under way.
Separate investigations have indicated that about 90% of the stolen Bitcoin has not moved on-chain. Analysts have, however, seen one attacker route 64 BTC through a Bitcoin mixer. The biggest identified attacker is still believed to hold about 1,159 BTC across seven addresses.
Hardware-wallet manufacturer Coinkite said the Coldcard weakness resulted from a firmware change introduced in March 2021 during the integration of a new cryptographic library.
The affected firmware did not use the intended hardware random-number generator when creating wallets. Instead, it used a deterministic pseudo-random generator supplied by MicroPython.
Block’s Bitcoin engineering and security team reached the same conclusion in an independent firmware review. Although Block said it had not finished empirical testing on every affected device, its analysis found that vulnerable firmware used the deterministic fallback to generate wallet seeds rather than the STM32 hardware random-number generator.
Coinkite has released emergency firmware updates for affected devices. It has warned, however, that installing the patched software alone does not secure wallets that were created with vulnerable firmware.
Users have been instructed to generate entirely new seed phrases on updated devices and move their Bitcoin to addresses created from those new wallets.
Coinkite said wallets generated using at least 50 private dice rolls were not affected by this particular random-number-generation flaw. It continues to recommend that users migrate to newly generated seeds.
