Boltz suspended its non-custodial Bitcoin swap service indefinitely on August 3, 2026, after reporting a sustained increase in automated, AI-assisted attacks against its infrastructure. The decision shows how machine-speed vulnerability probing can force even non-custodial services offline without directly compromising customer funds.
The pause disrupted swap functionality connecting Bitcoin’s mainchain with the Lightning and Liquid networks, affecting wallets and services that relied on Boltz as backend infrastructure. For integrators, the incident turns third-party availability into an immediate operational risk even when users retain control of their private keys.
Update: Boltz will stay disabled until further notice.
Our API remains available to process refunds cooperatively. In any case, unilateral refunds will work, as they do not depend on our infrastructure.
Our support team stays reachable.
To be clear: this is not a response to a… https://t.co/kv8zWt4bym
— Boltz – Non-Custodial Bitcoin Bridge (@Boltzhq) August 3, 2026
Non-Custodial Design Limits the Financial Damage
Boltz said it had contained several exploits over recent months, absorbing the associated losses internally. The team concluded that attackers were identifying and adapting attack paths faster than its developers could investigate, test and deploy fixes, creating a security-response imbalance that made continued operation irresponsible.
The company said multiple well-resourced groups appeared to be targeting its open-source infrastructure. After reviewing internal security scans, Boltz determined it could not safely restore swaps and warned users not to expect services to resume quickly, making the suspension an indefinite defensive measure rather than a short maintenance window.
DefiLlama showed approximately $180,860 in total value locked in Boltz around the time of the shutdown. That figure does not mean the same amount was trapped or stolen, because atomic swap architecture allows users to retain cryptographic control over their assets throughout the transaction process.
Boltz kept its API available for cooperative refunds of in-flight swaps, while its support team remained accessible to users and integration partners. The protocol also supports unilateral refund paths that do not require Boltz infrastructure, providing a recovery mechanism that separates service availability from ultimate asset ownership.
That distinction is the clearest demonstration of the non-custodial model’s value. An attack can disable routing, pricing or coordination systems, but it does not automatically give the attacker possession of customer Bitcoin, making availability failure materially different from a custodial insolvency or wallet compromise.
The interruption nevertheless affected connected products. Wallet providers relying on Boltz for Lightning or Liquid swaps had to disable functionality, seek replacement routes or warn users about failed transactions, showing how one specialized service can become concentrated infrastructure for several independent applications.
AI Attacks Raise the Cost of Open-Source Infrastructure
Boltz attributed the pressure to automated, AI-assisted probing that accelerated sharply before the shutdown. AI does not need to invent an entirely new class of exploit to change the threat environment; it can reduce the time required to inspect code, test inputs and modify attacks, giving adversaries a persistent speed advantage over small human security teams.
This asymmetry is particularly difficult for lean open-source projects. Public code improves auditability and collaboration, but it also gives attackers continuous access to implementation details, allowing automated offensive systems to search for weaknesses across every published update.
Solana Foundation security chief Michael Coates has argued that defenders will increasingly need autonomous systems capable of operating at machine speed. The Boltz episode supports that concern by showing manual patching and conventional incident response may no longer scale against continuously adapting automated attacks.
For custodians, wallets and payment providers, the immediate lesson is vendor concentration. A non-custodial integration may protect principal, but depending on one small external team for routing or settlement functionality can still create service interruptions, client-support burdens and reputational exposure.
Institutional counterparties should therefore assess staffing depth, security automation, incident escalation, dependency mapping and recovery procedures before treating community-maintained infrastructure as production-critical. Contracts and integration reviews should define who communicates incidents, how refunds operate and what fallback systems activate during an extended outage.
Treasury and risk teams should also distinguish custody risk from availability risk. Boltz’s architecture prevented the pause from becoming a direct loss of user funds, but integrations still lost functionality, demonstrating why operational resilience must be assessed separately from private-key control.
Developers can reduce exposure through defense-in-depth measures such as continuous automated testing, runtime anomaly detection, independent audits, rate limits and segmented infrastructure. Integrators should maintain alternative routing providers where possible so that one vendor suspension does not disable an entire payment or liquidity workflow.
The episode will also increase pressure for clearer incident reporting from decentralized and non-custodial service providers. Users and counterparties need timely disclosure of affected components, recovery paths and known losses, making transparent communication a core security control during infrastructure emergencies.
Boltz prioritized asset integrity and recoverability over uptime, a decision that protected users but exposed the limitations facing small teams under sustained automated attack. Its eventual return will depend on whether the project can establish a defensive model capable of matching the speed, persistence and adaptability of machine-assisted adversaries.

