Zeus Wallet Halts Services Following Cybersecurity Incident
In a recent update, Zeus Wallet has temporarily halted its services following a cybersecurity incident, reassuring users that their assets remain safe and untouched. The company revealed the situation on August 5, noting that although the attack was contained within hours, they would keep their systems offline for a thorough audit of their infrastructure before operations can resume.
Details of the Incident
Evan Kaloudis, the founder of Zeus, emphasized in a blog post that early investigations indicate the breach was confined to the company’s own infrastructure without affecting customer funds. The self-custodial wallet service for Bitcoin users has implemented these measures to ensure security and maintain trust within their community, although no timeline has been established for when services will be restored.
During this outage, Zeus has assured customers who experienced the closure of their Lightning Service Provider (LSP) channels that they will receive replacements once systems are back online. Affected users are encouraged to reach out to customer support via the Zeus mobile wallet app, although they may experience longer wait times due to an influx of inquiries related to the incident.
Context and Related Updates
This incident comes shortly after Zeus announced an update regarding its functionality, which included the disabling of its swap features in reaction to the suspension of the non-custodial Bitcoin swap provider, Boltz. Although both updates were communicated separately, Zeus has not indicated any direct correlation between the cybersecurity breach and the suspension of the swap service.
Kaloudis noted that this incident highlights the ongoing development efforts by Zeus in creating trusted execution environments, also referred to as enclaves, and their work on the Validating Lightning Signer (VLS) project aimed at improving their infrastructure’s defenses against such attacks.
Broader Implications for Security
Despite the cybersecurity classification of the event, Zeus has not revealed details about how the breach occurred or any potential impacts to systems beyond their infrastructure. This focus on security comes in the wake of increased scrutiny and heightened risk awareness within the Bitcoin community, following the recent Coldcard wallet attacks.
To further bolster security, the volunteer-led Bitcoin Red Team has initiated a comprehensive review of various Bitcoin wallets and infrastructure software, funded by OpenSats. They have already identified thousands of potential vulnerabilities within a mere two days, bringing to light ongoing threats in the ecosystem, with several critical issues shared privately with project maintainers while fixes are in the works.
The recent surge in Bitcoin thefts has also drawn attention to vulnerabilities in certain Coldcard wallet firmware versions, which reportedly led to losses exceeding 1,596 BTC across multiple attacks. Investigators have observed that around 90% of the stolen cryptocurrency remains untouched on the blockchain, raising alarms about security practices and the need for enhanced protective measures for users.
Conclusion
With all these events unfolding, Zeus Wallet’s immediate focus will be completing its internal audit and preparing to reinstate full services while also processing replacement channels for users that were affected so that confidence can be restored in their systems and operations.