Boltz halts Bitcoin swaps after AI-assisted probes
Boltz suspended Bitcoin swaps after AI-assisted probes and exploits outpaced its team’s ability to patch systems; the company warned users may move to larger custodial platforms.
Boltz suspended its Bitcoin swap product and said swaps will remain offline until further notice after automated, AI-assisted probing and exploits accelerated beyond the team’s capacity to patch systems. Support and refund APIs stayed available while swaps were paused.
The service bridged on-chain Bitcoin, the Lightning Network and Liquid, and used a non-custodial design meant to keep users in control of their coins during swaps. Boltz’s post said the design preserved refund paths and protected user balances through months of attacks, but exploit losses were recorded on the company’s books and the team “could no longer keep pace.”
Boltz described attackers using automated, AI-assisted scans to find vulnerabilities faster than the team could validate reports, produce fixes, test them and deploy patches. The company characterized the defensive work as a chain of tasks-confirming findings, assessing severity, building fixes, testing and shipping-that requires automation and staffing to operate at machine speed.
Large technology firms report using automated triage to filter noise, reproduce bugs and route issues to the right engineers. Those firms also report using large language models to generate candidate fixes, separate automated agents to review tests, and human sign-off before deployment.
Security teams and agencies have documented similar trends. An analysis by Anthropic of 832 banned accounts found increased use of AI to scan targets and collect data. A major threat intelligence group has described generative models being used in offensive workflows. In June, a federal cybersecurity agency advised that AI is accelerating vulnerability discovery and shortening patch windows to days.
Industry monitoring firms reported related shifts in attack patterns. One analysis found infrastructure and operational compromises accounted for about 76% of crypto hack losses in the first half of 2026 while representing roughly 15% of incidents. Another report identified wallet compromise as the costliest category over the same period, with more than $444 million stolen across 33 incidents. Researchers say attackers have targeted signing infrastructure, credentials and operational controls rather than attempting to break underlying cryptography.
Security groups and open-source foundations are building tools to triage and validate AI-generated vulnerability reports before they reach maintainers. Open-source project managers have warned that a flood of low-quality, AI-written reports can consume triage time even when no true vulnerability exists.
Smaller crypto teams face rising defensive costs and shorter patch windows. Options noted by security practitioners include raising security-specific funding, outsourcing security operations, merging with larger providers, narrowing product offerings, or suspending higher-risk services. Shared triage systems and pooled AI defenses are being discussed as ways to replicate automated discovery-to-patch pipelines used by larger firms.
Boltz’s pause affected its swap product only; support and refund functions remained operational. The company posted that it would not resume swaps until it could validate fixes and restore safe operations. The incident adds to industry data on AI-assisted offensive activity and ongoing efforts to adapt defensive tooling and staffing.








