Incident case file
Sign in to watchZEUS Lightning Wallet Infrastructure Compromise
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAugust 5, 2026 (within a few hours prior to public disclosure): ZEUS, a non-custodial Bitcoin Lightning wallet and Lightning Service Provider, detects a cybersecurity incident affecting its own internal infrastructure. The attack is successfully mitigated before any customer funds are lost or placed at risk at any point. August 5, 2026, 21:14:59 UTC: ZEUS founder Evan Kaloudis publishes an official blog post titled 'Security Update - August 5th, 2026' on the company's official blog (zeusln.com/blog). August 5, 2026, 21:19:01 UTC: ZEUS's official X account (@ZeusLN) publicly confirms the incident, stating: 'ZEUS infrastructure is temporarily offline following a cybersecurity incident that occurred within the last few hours. The attack has been mitigated. Out of an abundance of caution, we are keeping services offline while we conduct a comprehensive audit of all systems before restoring operations. No customer funds were lost. No customer funds are at risk.' SlowMist Hacked's official incident database independently confirms the event with 'Amount of loss: 0' and specifically notes there is 'no evidence of a Lightning node software vulnerability' — the compromise is explicitly scoped to ZEUS's own proprietary infrastructure rather than to the underlying open-source Lightning Network protocol implementation itself. August 6, 2026: Multiple media outlets, including Cryptopolitan, Crypto.news, and Cryptorank, report on the incident, framing it within the context of it being the third Lightning-infrastructure-related service disruption across the industry within a 72-hour window, following the separate Boltz and AQUA outages earlier the same week. August 7, 2026, 03:16:46 UTC: ZEUS updates its official blog post with additional details as its internal security audit progresses toward completion. Service restoration proceeds incrementally over the following days, with any Lightning Service Provider channels that were closed during the incident scheduled to be replaced once full operations resume. No attacker identity, specific attack vector technical details, or formal attribution to any threat actor or group have been publicly disclosed as of the close of the reporting window.
Sources and coverage
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlex.comhttps://x.com/ZeusLN/status/2085113369367871605
- Articlecryptopolitan.comhttps://www.cryptopolitan.com/zeus-pulls-infrastructure-offline-after-hack-third-lightning-outage-in-a-week/
- Articlecrypto.newshttps://crypto.news/zeus-wallet-takes-infrastructure-offline-after-cybersecurity-incident
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)