AI 協助的駭客攻擊迫使 Boltz 關閉 Bitcoin 換幣服務
重點速覽
- •Boltz 表示其 swaps 已無限期停用,且沒有恢復服務的時間表。
- •公司報告稱,過去幾個月自動化 AI 協助探測明顯增加,並出現多起已控制的漏洞利用。
- •Boltz 表示用戶資金從未面臨風險,因為 swaps 使用 hashed timelock contracts,且公司不託管幣。
- •API 仍可用於 cooperative 與 unilateral refunds,且支援團隊仍可聯繫。
- •Bull Bitcoin 與 Aqua Wallet 也回報與 Boltz 停擺相關的服務中斷,並在尋找替代路由方案。

週一,Boltz 無限期關閉了其 swaps。這項非託管服務讓用戶可在 Lightning Network 與 Bitcoin 基礎層之間轉移 Bitcoin;該公司表示,持續升高的 AI 協助攻擊浪潮使其無法安全地繼續運作。
Boltz 指出,Lightning 用戶以及支撐 Bitcoin 很大一部分支付基礎設施的小型開源團隊,正越來越直接面對攻擊者如今的運作速度。
Boltz 指出攻擊者迭代速度已快於修補速度
Boltz 在 X 上表示,swaps 已經關閉,且“until further notice”,目前沒有任何可能恢復的時間表。
這家 Bitcoin bridge builder 表示:“To be clear: this is not a response to a single incident.” 在過去幾個月中,公司觀察到其系統遭遇持續增加的自動化、AI 協助探測,並處理了幾起漏洞利用事件,且每一起都已被控制。
Boltz 表示:“Attackers now iterate faster than a team our size can find and patch.” 最近的安全掃描使公司無法在負責任的前提下重新開啟 swaps,因為其“being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes”。
該公司將此變化描述為“a major paradigm shift for Bitcoin services operating on an open source stack.” 並告訴用戶,“Do not expect swap services to resume shortly.”
Update: Boltz will stay disabled until further notice.
Our API remains available to process refunds cooperatively. In any case, unilateral refunds will work, as they do not depend on our infrastructure.
Our support team stays reachable.
To be clear: this is not a response to a…
— Boltz – Non-Custodial Bitcoin Bridge (@Boltzhq) August 3, 2026
Boltz 確認沒有人損失資金,因為公司從未取得客戶幣的控制權。這些 swaps 是透過 hashed timelock contracts 執行,這種機制會讓交易要麼完整完成,要麼在單一區塊內回復。
swaps 在一般 BTC、Lightning BTC 與 Liquid Network BTC 之間轉移價值。Boltz 表示:“No user funds were ever at risk,” 並補充說:“Losses were ours alone.”
Boltz 尚未披露其交易量,而 DeFiLlama 顯示其總鎖倉價值約為 ~$262,000。API 目前仍在運作,因此用戶可進行 cooperative refunds;unilateral refunds 也同樣可行,因為它們不依賴 Boltz 的基礎設施。
AI 越來越常出現在 Bitcoin 駭客攻擊中
Bull Bitcoin 告知用戶,其錢包中的 Lightning payments 與 Liquid-to-Bitcoin swaps 現在將會“fail without explanation”,同時公司正在尋找修復方案。Aqua Wallet 也發布了類似通知,並表示正與 Boltz 合作,為 Lightning swaps 尋找替代路徑。
這次停擺對任何在開源技術棧與小團隊環境中建構服務的人都是警示。隨著攻擊量上升,快速修補與持續監控變得更難維持;Swan 共同創辦人 Yan Pritzker 表示,AI 攻擊者正變得更複雜,而維持企業級安全的成本“will price out many innovative startups”,即使是處理客戶資金、非託管的服務也不例外。
AI 軟體也被認為與 Coldcard 的 seed-phrase 漏洞利用有關;Coldcard 是一款硬體錢包,涉及超過 $100 million 被盜 Bitcoin。Cryptopolitan 也報導了 DeFi 中相同的趨勢,GoPlus Security 表示,在 48 小時內的四起 smart-contract 攻擊中,超過 $1.5 million 被盜走。
A16z crypto 發現,當一個現成 AI agent 被提供結構化攻擊知識後,利用已知漏洞的成功率從 10% 提升到 70%。
如果你正在閱讀這篇文章,你已經領先一步。透過我們的 newsletter 保持領先。