ZEUS (@ZeusLN), a self-custodial Bitcoin Lightning Network wallet, took its infrastructure offline Wednesday after a cybersecurity incident, with founder @evankaloudis saying the attack has b
ZEUS (@ZeusLN), a self-custodial Bitcoin Lightning Network wallet, took its infrastructure offline Wednesday after a cybersecurity incident, with founder @evankaloudis saying the attack has been contained and services will remain down while the team audits all systems.
The company posted details on X and in a blog post, saying it mitigated the attack within hours and found no evidence the incident affected external Lightning node software. Founder Evan Kaloudis wrote that the investigation so far suggests the incident was limited to ZEUS infrastructure, though no technical details or restoration timeline were disclosed.
ZEUS said its core custody protections remained intact during the incident. Some LSP (Lightning Service Provider) channels were closed as a precautionary measure and will be replaced once service resumes. No customer funds were lost or placed at risk.
Part of a Broader Lightning Outage Wave
The ZEUS incident makes it the third prominent Lightning provider to suspend services within roughly 72 hours, following earlier interruptions at Boltz and AQUA. The cluster of outages has raised concerns about the safety of Lightning infrastructure providers, though analysts stress the issues do not reflect a vulnerability in the Bitcoin Lightning Network itself.
Earlier in the week, ZEUS had already disabled its swap feature after Boltz, a non-custodial Bitcoin swap service, halted operations. The swap suspension and the cybersecurity incident are separate events, but both reduced functionality for some users.
Looking ahead, ZEUS said it plans to work on trusted execution environments, also known as enclaves, and the Validating Lightning Signer (VLS) project to strengthen signing infrastructure and reduce single points of failure.
A Difficult Week for Bitcoin Self-Custody
The ZEUS attack lands in an already bruising week for $BTC holders. Beginning July 30, 2026, attackers exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet to systematically drain bitcoin from affected devices. The flaw traces to a March 2021 firmware release and a build configuration error that caused seed generation to fall back on a weak software random number generator rather than the device's hardware-based source of entropy. At least four waves of theft have followed, with Galaxy Research's running tally of losses standing near 1,816 $BTC, worth close to $116 million, drained from more than 5,200 addresses.
Coinkite has since released patched firmware, and affected users are advised to migrate funds to newly generated, unaffected seeds.
Sources:Cryptopolitan: ZEUS pulls infrastructure offline after hack, third Lightning outage in a weekTRM Labs: Inside the $116 Million Coldcard HackCoinDesk: Coldcard urges users to move bitcoin as active wallet exploit continues