
Boltz suspended its Bitcoin swap services indefinitely on August 3 after reporting months of automated, AI-assisted probing and several contained exploits. According to the latest statement, the noncustodial bridge provider said the attacks had accelerated sharply in recent days, leaving its development team unable to deploy fixes as quickly as attackers adapted their methods. The company described the suspected attackers as 'multiple resourceful groups' but did not identify them or provide independent evidence confirming who conducted the attacks. As reported by crypto.news, the 'AI-assisted' nature of these attacks represents a significant shift in threat models, with automated probing and load at scales small teams were never built to absorb. The halt began at 5:54 a.m. ET, with the Lightning and Liquid swap rails cut off from wallets such as Aqua and Bitcoin Bull. The team stated that after reviewing security scans, 'we cannot responsibly re-enable Boltz swaps' given the current threat landscape, with the suspension expected to last 'until further notice'.
Boltz stated that no customer funds were exposed during the incidents because users retain control of their assets throughout its atomic swap process. As reported by crypto.news, the company said it absorbed the losses associated with the contained exploits because it operates as a fully bootstrapped business. The service's API remains online for cooperative refunds, and users can complete unilateral refunds without relying on Boltz infrastructure. The company's support team remains available for customers with unfinished transactions. According to ParadiseTeam, this represents an availability problem, not a solvability one, as non-custodial services never hold user coins in the first place - users keep their keys while the service routes the swap. The company noted it could not 'responsibly re-enable Boltz swaps' given the current threat landscape, with the team stating 'What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly.'
The market treated the Boltz outage as a contained incident rather than a systemic threat, with Bitcoin trading near ₹63,626 and down just 0.3% on the day. As reported by ParadiseTeam, the incident is viewed as minor fear, not a capitulation trigger, with no forced-seller cascade or solvency domino effect observed. The liquidity picture shows that when infrastructure scares occur during an already cautious market, they remove reasons to chase rather than spark selling on their own. The 'AI-assisted' nature of these attacks highlights a growing gap between attack tooling costs and defense budgets at small non-custodial services, potentially leading to a steady drip of infrastructure incidents that raises perceived operational risk of holding assets in swap services. This represents a concerning trend as similar attacks have recently affected other protocols, including the Coldcard firmware vulnerability that has so far drained $114 million in Bitcoin starting around July 30. The same week saw a major Coldcard hardware wallet exploit, with two significant Bitcoin-layer security incidents in the span of a few days making the entire ecosystem nervous. BTC Sessions summarized the immediate damage: **'wallets using Boltz for Lightning swaps
The shutdown affected multiple wallet services that rely on Boltz infrastructure. According to crypto.news, Bull Bitcoin said the shutdown temporarily disabled Lightning payments and conversions between Liquid Bitcoin and onchain Bitcoin within its wallet. ZEUS also disabled its own deployment of the open source Boltz stack, while Aqua notified users that the service suspension affected its swap functions. Neither wallet reported customer asset losses, and Bull Bitcoin said it was evaluating several replacement options. As reported by ParadiseTeam, the quiet ending scenario where Boltz processes refunds smoothly without drama would cause this story to fade from the tape entirely within days, allowing the market to return to trading macro trends. Francis Pouliot, CEO of Bull Bitcoin, said the company was working to restore the impaired swap capabilities, warning that 'until then those functions will fail without explanation' and that the company is 'immediately shifting our priorities' to restore Lightning payments and Liquid-to-bitcoin swaps. Samson Mow, CEO of JAN3 (the firm behind the Aqua wallet), said its team was working with Boltz to restore functionality to optimal levels, with Aqua having 'offered to help Boltz address issues in their infrastructure' and noting that user funds on Aqua remain safe and under user control. For users who relied on Boltz for regular swaps between Lightning and Liquid, the immediate task is finding alternatives, as Boltz carved out a niche precisely because few other services offered the same combination of non-custodial security and cross-layer flexibility.
The Boltz attacks represent part of the worst week for bitcoin security in years, occurring alongside the Coldcard hardware wallet exploit that has drained roughly $114 million in BTC since July 30. According to CoinPedia, similar attacks took place recently, including the Metronome synthetic asset shortfall of July 31, where an embedded oracle delay led to the loss of about $16 million. Another significant incident was the August 1 Adform script poisoning, which interfered with the wallet address copy-paste feature. Lucas Ferreira of the Bitcoin non-profit Vinteum noted that 'Boltz has a brilliant team, but it's a small team facing increasingly sophisticated, AI-powered groups of hackers.' This follows Boltz's earlier suspension on August 1 of its Ethereum Virtual Machine (EVM) swaps, citing an EVM integration bug, with the latest attack focusing away from EVM and onto the Bitcoin ecosystem. For open-source projects specifically, the threat is amplified as their codebases are public by design, which normally makes them more secure through more eyes on the code, but when AI can scan those same public codebases and generate exploit strategies at machine speed, the equation flips. The transparency that makes open-source trustworthy also makes it a richer target for automated reconnaissance.