Boltz suspended its Bitcoin swap services indefinitely on Aug. 3 after reporting months of automated, AI assisted probing and several contained exploits. 

Summary

  • Boltz suspended swaps indefinitely after reporting months of automated, AI-assisted probing and several contained exploits.
  • The company says attackers now adapt faster than its team can identify and patch flaws.
  • No user funds were at risk, while Boltz says it absorbed all operational losses itself.
  • Refund APIs and support remain available, but the protocol has provided no reopening date yet.
  • Bull Bitcoin, Aqua and ZEUS reported service disruptions tied to their reliance on Boltz swaps.

The noncustodial swap provider said the attacks had accelerated sharply in recent days, leaving its development team unable to deploy fixes as quickly as attackers adapted their methods.

The team said it could not responsibly restore swaps while it remained under active attack and reviewed findings from recent security scans. Boltz described the suspected attackers as “multiple resourceful groups,” although it did not identify them or provide evidence independently confirming who conducted the attacks.

Boltz swap shutdown followed an earlier EVM warning

The wider shutdown followed an Aug. 1 notice concerning a bug in Boltz’s Ethereum Virtual Machine integration. The service initially disabled swaps involving assets such as USDT, USDC, WBTC, TBTC and RBTC while stating that Bitcoin, Lightning and Liquid swaps remained operational. Two days later, it stopped all swap services.

Boltz operates infrastructure connecting Bitcoin mainnet with the Lightning Network, Liquid and other supported networks. Its public API powers the main web application and outside integrations. Official documentation advises developers to use supported software development kits because they manage swap cryptography, recovery procedures and transaction states.

Moreover, Boltz said no customer funds were exposed during the incidents because users retain control of their assets throughout its atomic swap process. The company also said it absorbed the losses associated with the contained exploits because it operates as a fully bootstrapped business. Those statements remain company claims because Boltz has not published a technical incident report or independent security review.

The service’s API remains online for cooperative refunds. Users can also complete unilateral refunds without relying on Boltz infrastructure, according to the company. Its support team remains available for customers with unfinished transactions.

The distinction shows how noncustodial architecture can limit custody losses without preventing operational disruption. Users may retain their Bitcoin, but they cannot initiate new swaps through the affected service until operations resume or integrated wallets introduce alternative providers.

Wallets are seeking replacements for Boltz infrastructure

Bull Bitcoin said the shutdown temporarily disabled Lightning payments and conversions between Liquid Bitcoin and onchain Bitcoin within its wallet. Standard Bitcoin transfers, Liquid transfers, wallet restoration and storage functions continued operating normally.

The company said it was evaluating several replacement options and promised a separate mechanism for customers wishing to convert Liquid Bitcoin into onchain Bitcoin. It added that its Liquid Federation membership allows it to conduct conversions without depending on a third party.

ZEUS also disabled its own deployment of the open source Boltz stack, while Aqua notified users that the service suspension affected its swap functions. Neither wallet reported customer asset losses.

As crypto.news previously reported, Blockstream had integrated Boltz into its mobile wallet to support Lightning and Liquid swaps. The shutdown shows how applications that use shared swap infrastructure can face service interruptions even when their core wallet functions remain available.

Boltz has not provided a reopening date

Boltz warned users not to expect swap services to resume soon. It has not published a remediation timetable, detailed vulnerability list or conditions that must be met before operations restart. The team said it would provide another update after assessing its options.

The company’s attribution to AI assisted activity also remains difficult to verify without technical indicators. Automated scanning can increase the speed and volume of attacks, but Boltz has not explained how it determined artificial intelligence played a role.

In related coverage, crypto.news reported that Solana Foundation security chief Michael Coates expects artificial intelligence to strengthen both attackers and defensive systems. Boltz’s next update is expected to clarify whether it will introduce automated monitoring, outside audits or changes to its open source infrastructure before restoring swaps.



Source link

Shares:
Leave a Reply

Your email address will not be published. Required fields are marked *