Bitcoin Bridge Boltz Halts Swap Service Indefinitely Over AI-Assisted Attacks
The non-custodial platform cites machine-speed cyberattacks outpacing developer fixes, though user funds remain secure.
Bitcoin swap service Boltz has indefinitely suspended its exchange operations after a wave of automated, AI-driven cyberattacks exposed vulnerabilities faster than developers could deploy fixes.
The platform, which facilitates non-custodial transfers between the Bitcoin blockchain and the Lightning Network, disclosed that security audits revealed active targeting by multiple well-resourced attack groups.
Despite the suspension, Boltz stressed that customer assets were never endangered because the protocol does not take custody of user funds. Data from DeFiLlama indicates the service holds roughly $262,000 in total value locked, though overall transaction volume figures are not published.
“To be clear: this is not a response to a single incident,” the company said in a series of statements on social media platform X on Monday. “Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.”
Boltz stated that while core swap operations are disabled, customer support remains active. The company’s API continues processing cooperative refunds, and unilateral refunds remain fully functional without depending on Boltz’s infrastructure.
“After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes,” the company wrote, describing the trend as a “major paradigm shift for Bitcoin services operating on an open source stack.”
The shutdown reflects broader industry anxiety over AI-enhanced cybersecurity risks. On Tuesday, Ledger Chief Technology Officer Charles Guillemet warned that attackers are leveraging AI to uncover code vulnerabilities “at machine speed.” His comments came as losses from an exploit targeting Coldcard neared $130 million.
Boltz declined to estimate when services might resume, adding: “We can’t give an ETA as of this time, but will provide an update once we know more.”









