Boltz Halts Bitcoin Swaps Citing AI-Assisted Attacks
Key Takeaways
- •Boltz said its swaps are disabled until further notice and it has no timeline for restoring the service.
- •The company reported a steady increase in AI-assisted probing and several contained exploits over recent months.
- •Boltz said user funds were never at risk because swaps use hashed timelock contracts and it does not take custody of coins.
- •The API remains operational for cooperative and unilateral refunds, and support is still available.
- •Bull Bitcoin and Aqua Wallet also reported disruptions linked to the Boltz shutdown while they look for alternative routing options.

On Monday, Boltz indefinitely shut off its swaps. The non-custodial service that lets users move Bitcoin between the Lightning Network and Bitcoin’s base layer said a rising wave of AI-assisted attacks had made it unsafe to keep operating.
Lightning users and the small open-source teams that support much of Bitcoin’s payment plumbing are increasingly exposed to how quickly attackers can now operate, according to Boltz.
Boltz says attackers are iterating faster than fixes
Boltz said in posts on X that swaps are off “until further notice,” with no timeline for a possible return.
“To be clear: this is not a response to a single incident,” the Bitcoin bridge builder said. Over the past few months, it had seen a steady increase in automated, AI-assisted probing of its systems and had dealt with several exploits, each of which was contained.
“Attackers now iterate faster than a team our size can find and patch,” Boltz said. The recent security scans left the company unable to responsibly turn swaps back on while it was “being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes.”
The company described the change as “a major paradigm shift for Bitcoin services operating on an open source stack.” It told users, “Do not expect swap services to resume shortly.”
Update: Boltz will stay disabled until further notice.
Our API remains available to process refunds cooperatively. In any case, unilateral refunds will work, as they do not depend on our infrastructure.
Our support team stays reachable.
To be clear: this is not a response to a…
— Boltz – Non-Custodial Bitcoin Bridge (@Boltzhq) August 3, 2026
Boltz confirmed that no one lost funds because it never takes control of customer coins. The swaps are executed through hashed timelock contracts, a mechanism that either completes a trade in full or reverses it within a single block.
Swaps move value between regular BTC, Lightning BTC, and Liquid Network BTC. “No user funds were ever at risk,” Boltz said. It added, “Losses were ours alone.”
Boltz has not disclosed its transaction volumes, while DeFiLlama showed its total value locked at about $262,000. The API is still running and operational, so users can process cooperative refunds, and unilateral refunds work as well because they do not depend on Boltz infrastructure.
AI is increasingly appearing in Bitcoin hacks
Bull Bitcoin told users that Lightning payments and Liquid-to-Bitcoin swaps in its wallet would now “fail without explanation” while it searches for a fix. Aqua Wallet issued a similar notice and said it was working with Boltz to find an alternative route for Lightning swaps.
The shutdown highlights a broader operational strain for Bitcoin services that rely on open-source codebases and small teams, where rapid patching and continuous monitoring can become harder to sustain as attack volume rises. AI attackers are becoming more sophisticated, and the cost of maintaining enterprise-grade security “will price out many innovative startups” working on services tied to client funds, even non-custodial ones, said Swan co-founder Yan Pritzker.
AI software has also been linked to a seed-phrase exploit of Coldcard, a hardware wallet implicated in more than $100 million in stolen Bitcoin. Cryptopolitan also reported the same trend in DeFi, where GoPlus Security said more than $1.5 million was drained in four smart-contract attacks in 48 hours.
A16z crypto found that the success rate of an off-the-shelf AI agent exploiting known vulnerabilities jumped from 10% to 70% once it was fed structured attack knowledge.
If you're reading this, you’re already ahead. Stay there with our newsletter.