Boltz, a non-custodial service that lets users move Bitcoin between the Lightning Network and the base blockchain layer, has suspended its swap functionality indefinitely. The company said the decision was driven not by a single breach but by a steady escalation in automated attacks targeting its infrastructure.
In a statement, Boltz said it had observed
a steady rise in automated, AI-assisted probing of our infrastructure
over recent months. While the team managed to contain multiple attempted exploits, it ultimately concluded that attackers were moving faster than its engineers could keep up with, warning that
attackers now iterate faster than a team our size can find and patch
.
Because Boltz operates as a non-custodial platform, the company emphasized that no user funds were placed at risk by the suspension. Data from DeFiLlama shows the protocol's total value locked stood at roughly $262,000 at the time swaps were paused, a relatively small figure that limited the potential blast radius of any successful exploit.
What Still Works
Boltz clarified that while new swaps are off, its API remains available to process cooperative refunds, and unilateral refunds continue to function independently of the rest of the system. Customer support also remains operational for affected users.
Part of a Broader Pattern
The shutdown follows warnings from other corners of the industry about AI's growing role in both offense and defense within crypto security. Ledger Chief Technology Officer Charles Guillemet said this week that AI now allows attackers to scan code and identify weaknesses
at machine speed
, even as defenders adopt similar tools to keep pace.
Guillemet's comments came in the wake of an exploit affecting hardware wallet maker Coldcard, an incident that reportedly resulted in losses approaching $130 million and has rattled confidence across the self-custody ecosystem in recent weeks.
A Cautionary Signal for Smaller Teams
Boltz's decision to pull back rather than continue patching on the fly illustrates a growing dilemma for small infrastructure teams: as AI tooling lowers the barrier for attackers to probe and exploit code, projects with limited security resources may increasingly choose to pause operations rather than risk a breach.