AI-Driven Cyberattacks Force Boltz to Shut Down Bitcoin Swap Services
Boltz has suspended its Bitcoin swap services indefinitely after a sustained wave of AI-assisted cyberattacks overwhelmed its ability to keep pace with new exploits.
The non-custodial Bitcoin swap provider said attackers are now finding and adapting vulnerabilities faster than its small development team can identify and fix them, making it unsafe to restart normal operations.
The service, which enables trustless atomic swaps between the Bitcoin mainchain, the Lightning Network and the Liquid Network, said it has spent months containing multiple attacks.
Although each incident was successfully managed, the growing speed and sophistication of the attempts prompted the team to halt swaps while it reassesses its security.
Attackers Are Moving Faster Than Defenders
Boltz said it has seen a steady increase in "automated AI-assisted probing" of its infrastructure throughout 2026, with attacks accelerating sharply in recent days.
"Over the past months… we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch."
After conducting its latest internal security scans, the company concluded it could no longer safely operate its swap service while multiple well-resourced groups continued targeting its systems.
"After reviewing the results of our own recent security scans, we cannot responsibly re-enable Boltz swaps, especially as we are being actively targeted by what appear to be multiple resourceful groups while we race to deploy fixes."
Boltz added that it does not expect swap services to return anytime soon.
"What we are seeing is a major paradigm shift for Bitcoin services operating on an open source stack, and it needs careful analysis. Do not expect swap services to resume shortly."
Users' Bitcoin Remains Safe Despite Service Halt
Despite suspending swaps, Boltz stressed that no user funds have been at risk because its platform is non-custodial.
Users maintain full control of their Bitcoin throughout every transaction, with swaps secured through advanced cryptographic mechanisms rather than assets being held by the platform.
The company said losses from the contained exploits were absorbed internally.
Its API will remain online to process refunds for incoming swaps, while its support team will continue assisting users.
According to DefiLlama, Boltz had a total value locked of around US$262,187 at the time of writing.
The disruption has also affected services that rely on Boltz's infrastructure.
Wallets and platforms including Aqua, Bull Bitcoin and ZEUS temporarily lost swap functionality while their teams worked to restore affected features.
Growing Calls for Automated AI Defence
The incident has renewed concerns about AI-powered attacks targeting cryptocurrency infrastructure, particularly open-source projects whose publicly available code can be rapidly analysed by automated systems.
Michael Coates, chief information security officer at the Solana Foundation, warned in July that traditional security teams can no longer keep pace with AI-assisted threats.
Coates said,
"We're at a tipping point as an industry where humans cannot scale to meet these threats. The only path forward we have is to have autonomous defense that operates at the speed of machines."
Boltz is not alone in facing this challenge.
PayPerQ, an AI platform that accepts Bitcoin and other cryptocurrencies for payments, said it has also experienced frequent attacks believed to be AI-powered.
"We've been fighting off exploits every other week for several months, most of which we believe are AI-powered. It's a very dangerous time out there."
The shutdown also follows a difficult period for Bitcoin security, with several high-profile incidents affecting the ecosystem in recent days, including the widely reported Coldcard firmware vulnerability that has resulted in significant Bitcoin losses.
Boltz's case differs because its non-custodial architecture protected customer funds, but the operational disruption shows how increasingly sophisticated AI-assisted attacks are placing growing pressure on smaller open-source development teams.