← Radar

Incident case file

Sign in to watch

ZEUS Lightning Wallet Infrastructure Compromise

Incident date 2026-08-04Last updated Aug 14, 2026

2 views

ResolvedBitcoin Lightning NetworkInfrastructure compromiseCluster: ZEUS-INFRA-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

MISSING — not publicly disclosed. The incident is described only as a cybersecurity attack targeting ZEUS's own infrastructure, mitigated before any on-chain fund drainage could occur.

Funds moved to

N/A — per SlowMist Hacked's official incident record, the confirmed amount of loss is $0. No customer funds were lost or placed at risk at any point during the incident.

Linked

ZEUS (ZeusLN) is a non-custodial Bitcoin Lightning Network wallet and Lightning Service Provider (LSP). No on-chain fund movement is associated with this incident in any way. Closed LSP payment channels affecting users during the outage were to be replaced once service was fully restored. This represented the third Lightning-related infrastructure outage across the industry within a 72-hour span, following closely on the heels of the separate Boltz and AQUA incidents earlier the same week.

Chronology

1 beat
  1. August 5, 2026 (within a few hours prior to public disclosure): ZEUS, a non-custodial Bitcoin Lightning wallet and Lightning Service Provider, detects a cybersecurity incident affecting its own internal infrastructure. The attack is successfully mitigated before any customer funds are lost or placed at risk at any point. August 5, 2026, 21:14:59 UTC: ZEUS founder Evan Kaloudis publishes an official blog post titled 'Security Update - August 5th, 2026' on the company's official blog (zeusln.com/blog). August 5, 2026, 21:19:01 UTC: ZEUS's official X account (@ZeusLN) publicly confirms the incident, stating: 'ZEUS infrastructure is temporarily offline following a cybersecurity incident that occurred within the last few hours. The attack has been mitigated. Out of an abundance of caution, we are keeping services offline while we conduct a comprehensive audit of all systems before restoring operations. No customer funds were lost. No customer funds are at risk.' SlowMist Hacked's official incident database independently confirms the event with 'Amount of loss: 0' and specifically notes there is 'no evidence of a Lightning node software vulnerability' — the compromise is explicitly scoped to ZEUS's own proprietary infrastructure rather than to the underlying open-source Lightning Network protocol implementation itself. August 6, 2026: Multiple media outlets, including Cryptopolitan, Crypto.news, and Cryptorank, report on the incident, framing it within the context of it being the third Lightning-infrastructure-related service disruption across the industry within a 72-hour window, following the separate Boltz and AQUA outages earlier the same week. August 7, 2026, 03:16:46 UTC: ZEUS updates its official blog post with additional details as its internal security audit progresses toward completion. Service restoration proceeds incrementally over the following days, with any Lightning Service Provider channels that were closed during the incident scheduled to be replaced once full operations resume. No attacker identity, specific attack vector technical details, or formal attribution to any threat actor or group have been publicly disclosed as of the close of the reporting window.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)