Newsroom
4 August, 2026 / News / AI / Tags: boltz, swaps, lightning, exploits, refunds

Non-custodial provider suspends services following months of automated probing and contained exploits, with no user funds exposed and refunds still available
Boltz, a non-custodial protocol enabling atomic swaps of Bitcoin and related assets across the mainnet, Lightning Network and Liquid Network, has disabled its swap services until further notice. The decision followed a sustained rise in automated, AI-assisted probing of its infrastructure and several contained exploits that the team said occurred over recent months.
In a statement issued on August 3, the project explained that attackers are now discovering and adapting exploits faster than its small development team can identify and patch them. Security scans conducted by the team itself reinforced the conclusion that restoring swaps would not be responsible while the service remains under active targeting by what appear to be multiple well-resourced groups.
The pace of activity accelerated sharply in the days leading up to the suspension. Boltz described the situation as a major shift for Bitcoin services built on open-source stacks and cautioned users not to expect a quick resumption of operations.
Two days earlier, on August 1, Boltz had already restricted swaps involving certain Ethereum Virtual Machine assets, including USDT, USDC, WBTC, TBTC and RBTC, after identifying a bug in its EVM integration. At that time, Bitcoin, Lightning and Liquid swaps continued to function. The full shutdown of all swap services followed on August 3.
Boltz operates as a bridge connecting Bitcoin mainnet with Lightning, Liquid and other supported networks. Its public API underpins both the main application and external integrations used by wallets and other tools. The protocol relies on advanced cryptography so that swaps either complete on both sides or fail cleanly, with users retaining control of their assets at every stage.
The project stated that no user funds have ever been at risk. Because the service is non-custodial, attackers gaining access to Boltz systems could not reach assets held in user wallets. The team, operating as a fully bootstrapped business, absorbed any operational losses associated with the contained incidents itself rather than passing costs to users.
Refund processes continue uninterrupted. The API remains available for cooperative refunds, and unilateral refunds can be completed without relying on Boltz infrastructure. Support staff remain reachable for users with unfinished transactions. Users holding incomplete swaps are advised to retain their swap identifiers, refund files and recovery information.
Several wallets that integrate Boltz infrastructure reported temporary disruptions. Bull Bitcoin stated that Lightning payments and conversions between Liquid Bitcoin and on-chain Bitcoin were affected, while standard transfers, Liquid transfers and core wallet functions continued normally. The firm is evaluating alternative providers and noted that its Liquid Federation membership allows independent conversion routes.
ZEUS disabled its own deployment of the open-source Boltz stack. Aqua informed users that swap functions were impacted; Samson Mow, CEO of JAN3, the company behind Aqua, said restoring Liquid and Lightning swaps is now a top priority and that the team has offered assistance to Boltz. Blockstream had previously integrated the service into its mobile wallet for Lightning and Liquid support.
At the time of the suspension, total value locked on the protocol stood in the low hundreds of thousands of dollars according to available data trackers, though this figure does not capture the full volume of transactions previously routed through the service.
The episode underscores a growing imbalance between the speed of automated attacks and the capacity of small development teams. Similar pressures have been reported by other crypto services. PayPerQ, a pay-per-prompt AI platform accepting cryptocurrency payments, said it has been contending with frequent exploits, many of which it suspects are AI-powered.
Michael Coates, chief information security officer at the Solana Foundation, has previously argued that the industry is approaching a point where human teams alone cannot match the pace of machine-driven threats and that autonomous defensive systems will be required.
Boltz has not released a detailed technical incident report, a list of specific vulnerabilities or a timetable for restoring services. The team indicated it will provide further updates after completing its assessment and determining whether additional monitoring, external reviews or infrastructure changes are necessary before any restart.
For the present, the service remains offline for new swaps while refund and recovery channels stay operational.









