---
title: "Zeus Wallet Goes Dark After Attack Shuts Lightning Channels"
date: 2026-08-06
author: "Kathleen Kinder"
featured_image: "https://coinlaw.io/wp-content/uploads/2026/08/zeus-wallet-goes-dark-after-cyberattack.jpg"
categories:
  - name: "Cryptocurrency"
    url: "/crypto.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Zeus Wallet Goes Dark After Attack Shuts Lightning Channels

Zeus Wallet took its infrastructure offline on August 5, 2026, after containing a cybersecurity incident that closed some customers’ Lightning Service Provider channels. The company said no customer funds were lost or placed at risk.

## Key Takeaways

- Zeus Wallet contained the attack within hours and found no sign of a Lightning node software flaw, founder Evan Kaloudis said.
- Zeus infrastructure appears to be the limit of the breach, based on the company’s investigation so far.
- Customers whose Lightning Service Provider channels closed during the attack will receive replacement channels once service returns.
- Zeus has not given a restoration date, explained the access method, or said how many customers lost service.
- Galaxy Research counts 1,596 BTC stolen in the separate Coldcard firmware thefts now driving ecosystem-wide code reviews.

## What Happened?

Zeus Wallet, a self-custodial Bitcoin Lightning Network wallet, pulled its infrastructure offline after mitigating an attack and has kept services down while it audits every system. Founder Evan Kaloudis said in the company’s [security update](https://zeusln.com/blog/security-update-2026-08-05/) that the team contained the attack within hours.

Kaloudis said in the post:

“

Based on our investigation so far, we believe this incident was limited to Zeus infrastructure.

Evan KaloudisFounder – Zeus Wallet





Zeus said its investigation has turned up no evidence that the incident began with a vulnerability in Lightning node software. The company kept services down “**out of an abundance of caution**” while the audit runs, and has set no restoration date.

> ZEUS infrastructure is temporarily offline following a cybersecurity incident.  
>   
> The attack has been mitigated. We are keeping services offline while we conduct a comprehensive audit of all systems before restoring operations.  
>   
> \*\*Customer funds were neither lost or at risk.\*\*
> 
> — ZEUS (@ZeusLN) [August 5, 2026](https://x.com/ZeusLN/status/2085113369367871605?ref_src=twsrc%5Etfw)

 ## Olympus channel closures exposed a centralized dependency

Zeus users hold their own private keys, so a server compromise did not put balances under an attacker’s control. Many of them still route payments through Olympus, the Lightning Service Provider Zeus operates, which is centralized infrastructure sitting outside the [Lightning protocol](https://coinlaw.io/bitcoin-lightning-network-usage-statistics/).

Customers whose LSP channels closed during the incident will receive replacement channels once services resume and Zeus can process requests. The company asked those users to contact support through the Help section of the mobile app and warned of slower responses while the backlog clears. Anyone who relied on a Zeus channel should check whether it is still open and plan an alternative route until service returns.

[Self-custody wallet](https://coinlaw.io/self-custody-wallet-statistics/) is often framed as freedom from provider risk. Key ownership and service availability are separate exposures, and this outage hit the second one. Zeus also disabled swap functionality on Monday after swap provider Boltz suspended its own platform, and has not linked the two events.

## What Zeus has not disclosed?

Zeus has confirmed the outcome while withholding the mechanics. Its disclosure describes an attack contained and an audit still running. It does not show how the attacker got in or how far the access reached.

The company has not answered these questions:

- **How the attacker gained access to Zeus infrastructure?**
- **Which internal systems were touched and whether any user data was exposed?**
- **How many LSP channels closed and how many customers lost service?**
- **Whether users must take any action before replacement channels arrive?**

Kaloudis said the incident reinforces work already under way on trusted execution environments, also called enclaves, and on the **Validating Lightning Signer (VLS) project**, which separates key signing from the Lightning node and screens transactions against preset policies. Zeus said that planned architecture is designed to help mitigate this category of attack, though it has not said whether either control covered the systems involved.

## Bitcoin security reviews accelerate after Coldcard attacks

Bitcoin developer Calle said the volunteer Bitcoin Red Team has begun reviewing wallets, libraries and infrastructure software using AI-assisted analysis with manual verification. The group examined 390 Bitcoin-related repositories in its first 29.8 hours and flagged **4,962** potential security issues, classifying 720 as high or critical severity. Reviewers have reproduced 21.4% of the findings, and Calle said several critical vulnerabilities went to maintainers privately.

That review push followed the [Coldcard hardware wallet thefts](https://coinlaw.io/coldcard-firmware-entropy-flaw-594-btc-swept/). Galaxy Research confirmed **1,596 BTC** stolen from roughly 7,300 addresses across three attack waves and suspects a fourth wave of 448.7 BTC from 709 likely victim addresses. Coinkite traced the flaw to a March 2021 firmware change that used a deterministic **MicroPython pseudo-random generator** during wallet creation instead of the STM32 hardware random-number generator, a conclusion Block’s Bitcoin engineering and security team reached independently.

Coldcard owners on affected firmware get no protection from the emergency update alone, because patched software does not repair a wallet created under the flawed generator. Coinkite has instructed them to generate new seed phrases on updated devices and move their [Bitcoin](https://coinlaw.io/bitcoin-statistics/) to addresses from the new wallets. Wallets built with at least 50 private dice rolls are not affected.

## CoinLaw’s Takeaway

Zeus caught the intrusion within hours and kept customer keys out of reach, the outcome a self-custodial design is built to produce. The service failure sits one layer below that design, in the Olympus LSP and the swap rails, where a provider outage still stops payments from moving. Anyone using **Bitcoin Lightning Network services** carries that operational exposure whoever holds the keys.

Disclosure is where this case stays open. Zeus has named the outcome and held back the mechanism, so no outside party can judge whether the same access path exists at other Lightning service providers. The wider [crypto cybersecurity picture](https://coinlaw.io/cybersecurity-in-cryptocurrency-statistics/) explains the urgency. The Red Team’s first scan surfaced hundreds of high-severity findings, and the Coldcard flaw sat in shipped firmware for years before investigators caught it. Most of the risk on display this week sits in the infrastructure layer that users never see.

Definition of Lightning Network. Link to full glossary entry follows the description.**Lightning Network**Bitcoinu0027s layer-2 protocol routing off-chain payments through bidirectional channels secured by HTLCs, settling in milliseconds at fractions of a cent.

[Read more](https://coinlaw.io/glossary/lightning-network/)