Tuesday, August 18, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
Bitcoin

Boltz bridge halt exposes Bitcoin Lightning’s reliance on single swap provider

Boltz suspended its non-custodial Bitcoin swap service indefinitely after AI-assisted attacks outpaced its team, disrupting linked wallets.

By Oliver Bennett · ·3 min read
Boltz bridge halt exposes Bitcoin Lightning’s reliance on single swap provider

Boltz, the non-custodial protocol that bridges Bitcoin’s mainchain with the Lightning Network and the Liquid sidechain, suspended all swap services indefinitely on 3 August after disclosing months of automated, AI-assisted attacks that its small development team could no longer patch quickly enough. The episode has laid bare how much of Bitcoin’s Lightning and Liquid ecosystem leans on a single piece of infrastructure to move funds across layers.

Boltz said the probing and contained exploits had escalated through July and into early August, culminating in a sharp spike shortly before the shutdown. The team described the incident as a “major paradigm shift” for open-source Bitcoin services, language that suggests operators are not anticipating a swift return to service. It attributed the campaign to “multiple resourceful groups”, though it did not name any attacker or publish independent verification of who was responsible.

An escalating warning before the full shutdown

The full suspension followed a narrower warning on 1 August, when Boltz disabled swaps involving Ethereum Virtual Machine-linked assets, including USDT, USDC, WBTC, TBTC and RBTC, while keeping native Bitcoin, Lightning and Liquid swaps running. Two days later, with attacks continuing to outpace fixes, the company halted all swap functionality across its platform.

Boltz operates as the underlying infrastructure for several third-party wallets rather than a consumer-facing app in its own right. Bull Bitcoin, Aqua and ZEUS all reported service disruptions as a direct consequence of their dependence on Boltz’s swap rails, according to both crypto.news and Crypto Briefing, leaving those platforms’ users without a route for cross-layer Bitcoin transactions until alternative providers emerge.

Funds unaffected, but the business absorbed the losses

Boltz maintains that no customer funds were put at risk during the incidents, crediting its non-custodial design, built on atomic swaps and hash time-locked contracts, under which users retain control of their assets throughout a transaction. The company said it absorbed the financial losses from the contained exploits itself, noting it is a fully bootstrapped operation without venture capital backing to cushion the impact on its operating budget.

Those assurances remain company statements for now, as Boltz has not yet published a formal technical incident report or an independent security audit of the events. Its refund API remains online for cooperative processing, and the firm has stressed that users can also complete unilateral refunds without relying on Boltz’s own infrastructure. Support channels remain staffed, but no timeline has been given for when swap services might resume.

Part of a wider stress test for Bitcoin-layer security

The shutdown lands in the same window as a separate incident affecting Coldcard hardware wallets, which Crypto Briefing reported had drained an estimated $114 million from user accounts beginning around 30 July — a figure that has not been independently confirmed elsewhere. Taken together, the two episodes have unsettled a Bitcoin security community already grappling with how automated, AI-driven reconnaissance tools change the calculus for open-source projects, whose public codebases are designed for scrutiny but can equally be mined for exploits at machine speed.

For institutions and infrastructure providers building on Lightning and Liquid, the episode underscores a concentration risk that has so far drawn less regulatory attention than custodial failures: a single, thinly resourced open-source bridge underpinning multiple consumer-facing wallets. Non-custodial architecture appears to have limited the damage to users’ holdings, but it has not prevented an operational outage that European wallet providers and their customers will now need to plan around.

Read more: Coldcard drain nears $89m, reviving debate over Bitcoin self-custody risk

Sources

More Bitcoin