Boltz, a leading non-custodial Bitcoin bridge, has announced the indefinite suspension of its swap services. The decision comes as a result of an escalating wave of AI-driven attack attempts that the company says have outpaced its ability to secure its operations effectively.
Boltz halts swap services amid AI-based security threats
Boltz operates a platform that allows users to move Bitcoin between the Lightning Network and Bitcoin’s main blockchain. In a statement on X, the company declared that all swap operations are paused “until further notice,” with no clear timeline for resuming normal activity.
The team clarified this is not due to a single breach, but rather a steady increase in automated, AI-assisted probing and several contained exploits over recent months. According to Boltz, these attack attempts have reached a pace where their small team cannot consistently identify and patch vulnerabilities before adversaries strike again.
In their official update, Boltz stated, “Attackers now iterate faster than a team our size can find and patch.” The company described this shift as a “major paradigm shift for Bitcoin services operating on an open source stack,” cautioning users not to expect a quick restoration of swap functionality.
Swap services will remain offline due to ongoing targeted attacks by multiple sophisticated groups, which prevent us from responsibly resuming operations while we race to deploy fixes. No user funds were at risk, and unilateral refunds are not dependent on our infrastructure.
The API remains available for processing refunds, and support services continue to operate. As Boltz functions as a non-custodial service, it never takes direct control of user funds. All swaps utilize hashed timelock contracts, ensuring trades either complete or reverse on-chain in a single block.
Boltz confirmed that, despite the attacks, “no user funds were ever at risk. Losses were ours alone.” The system facilitates transfers between traditional Bitcoin, Lightning BTC, and Liquid Network BTC. Total value locked on Boltz stood at approximately $262,000, according to DeFiLlama.
Users can still perform cooperative refunds through the API; unilateral refunds remain functional as they are not dependent on Boltz’s infrastructure.
Mini dictionary: Hashed timelock contract (HTLC), a smart contract used in the Bitcoin ecosystem to enable trustless swaps between parties, requiring either a successful secret reveal within a time limit or a transaction rollback to the original owner.
Impact on Lightning ecosystem wallets and partners
The sudden halt by Boltz has impacted other platforms integrated with its infrastructure. Bull Bitcoin, a Canadian Bitcoin services company, notified wallet users that Lightning payments and Liquid-to-Bitcoin swaps would “fail without explanation” while work continues on an alternative solution. Aqua Wallet has also issued a warning and is currently collaborating with Boltz to find different payment routes for Lightning swaps.
These developments underscore the risk for projects building on open-source financial stacks with limited personnel. Swan co-founder Yan Pritzker pointed out that small startups may be priced out by the escalating cost and complexity of maintaining robust security in an environment where AI-augmented attacks are rapidly advancing.
AI-powered attack tools mean the bar for maintaining enterprise-level security keeps rising, pushing multiple innovative Bitcoin builders out of the market, especially in non-custodial services.
AI threats rise across the crypto landscape
Incidents attributed to AI are becoming increasingly common in the cryptocurrency sector. AI tools have reportedly facilitated high-profile exploits such as the seed-phrase attack targeting Coldcard, a hardware wallet linked to thefts exceeding $100 million in Bitcoin. In the decentralized finance (DeFi) space, GoPlus Security reported four smart contract attacks across 48 hours, resulting in over $1.5 million in losses.
A16z crypto research found that the success rate of readily available AI agents in exploiting known software vulnerabilities soared from 10% to 70% when agents were provided with structured attack details, highlighting the rising severity of this threat in digital asset security.





USDT
AAPL
