AI Attack Freezes Boltz, Rattles Lightning Network Users

1 hour ago 16

Boltz, a company that lets people move bitcoin between the main blockchain, the Lightning Network, and the Liquid sidechain, shut down all of its swap services on Aug. 3 after months of automated attacks it said were increasingly powered by artificial intelligence (AI). The timing rattled bitcoiners because the disclosure landed almost alongside the Coldcard disaster, where a firmware failure had already emptied wallets and shattered confidence.

Key Takeaways

  • Boltz suspended Lightning and Liquid swaps on Aug. 3, 2026, after AI-driven attacks outpaced its team.
  • Three wallets, Aqua, Bull Bitcoin and Zeus, lost Boltz-powered swap access within hours of the halt.
  • Boltz had given no restoration timeline as of Aug. 4, 2026, while wallets search for backup providers.

The company took its systems offline early that morning without explanation. Hours later, it told users the pause would last “until further notice.” Boltz further explained on X that attackers had been probing its code for months, with the pace picking up sharply in recent days.

X screenshotImage source: X

“Attackers now iterate faster than a team our size can find and patch,” the company said in its statement. After running internal security scans, Boltz concluded it could not safely bring services back online while multiple capable groups were actively targeting it.

No customer funds were lost. Boltz never held user money directly. It relies on a system called hash time-locked contracts, which let two parties swap assets without either one taking custody of the other’s funds first. Users can still recover their money on their own, even with Boltz offline, and the company’s support channels remain open. Boltz covered the cost of the attacks that did get through.

Wallets Scramble to Adjust

The shutdown hit fast because several popular bitcoin wallets had built their Lightning features on top of Boltz’s infrastructure rather than running their own.

Aqua Wallet, built by JAN3, told users its Lightning and Liquid swap features would stay down for the foreseeable future, though regular bitcoin and Liquid transactions kept working. JAN3 CEO Samson Mow said restoring that functionality is now the company’s top priority and that Aqua is looking at several technical fixes, including offering to help Boltz directly. He said user funds remain fully in customers’ control and that other routes still exist to convert Liquid Bitcoin into regular bitcoin or USDT.

Bull Bitcoin reported similar problems, with Lightning payments and Liquid-to-Bitcoin conversions temporarily down in its app. Bull Bitcoin CEO Francis Pouliot stressed that the company is working to restore those features and guaranteed that no customer funds on Liquid will get stuck in the meantime.

X screenshotImage source: X

Zeus Wallet, which ran its own copy of Boltz’s open-source software, shut down its version of the service too. The company said its channel-based Lightning service and Lightning addresses still work normally. Blockstream also turned off in-app swaps in its wallet because of its reliance on Boltz, while keeping the rest of its Liquid features running.

X screenshotImage source: X

Not every wallet felt the impact. Seth For Privacy, chief operating officer at Cake Wallet, explained that Cake Wallet and its related payment tool Radarchat kept working through the outage because they don’t depend on Boltz. He said Cake Pay’s Lightning option was briefly knocked out because it used a Boltz plugin, but the team switched it to a different backend within hours.

Bitcoin Developers Question the “Lightning” Label

The outage reopened a longer-running argument about what counts as genuine use of the Lightning Network. Paul Sztorc, founder of Layertwo Labs and creator of the Drivechain proposal, argued that many wallets marketed as Lightning wallets actually depend on swap services like Boltz behind the scenes rather than routing payments through Lightning channels directly. Sztorc suggested on X that people who believe they use Lightning every day often can’t tell the difference between the two.

X screenshotImage source: X

Francisco Calderón, who built the peer-to-peer Lightning bots lnp2pBot and mostroP2P, said his own projects have faced constant attacks since launch and that his team now reviews code with AI assistance to keep up. He argued that if attack volume ever outpaces his team’s ability to respond, he would shut the bot down rather than risk it. Only his own node’s funds, not users’ money, would be at risk in that scenario.

Lightning Network Numbers Tell a Mixed Story

AMBOSS, a company that tracks Lightning Network data, pushed back on the idea that the outage signals a wider collapse. The firm explained that the disruption is concentrated in Boltz and Zeus swap infrastructure and one exchange-linked node, while total Lightning capacity keeps climbing and major exchange nodes continue to grow. Public node counts have stabilized, according to the company’s data, even as channels trend larger and more private.

Still, the episode points to problems that predate Boltz’s shutdown. A form of attack called channel jamming, which locks up payment capacity without completing transactions, has lacked a widely deployed fix for more than seven years. New Lightning users often can’t receive payments until they buy capacity from a service provider. And Bitcoin.com News has reported in the past that liquidity keeps concentrating among a small number of professional operators and cloud-hosted nodes.

What Comes Next

Boltz gave no timeline for restoring service as of Aug. 4. Aqua, Bull Bitcoin, Blockstream and Zeus are all now searching for backup swap providers or building redundancy so a single company’s outage can’t take down their Lightning features again. Bitcoin.com News is watching for updates from Boltz on when swaps might resume, whether alternative providers step in to fill the gap, and whether other small teams follow Calderón’s warning that AI-driven attacks could force them offline too.

The reports of AI-driven attacks arrive as investigators continue examining whether AI may have helped uncover the Coldcard vulnerability that enabled a remote hardware wallet exploit, ultimately leading to the theft of nearly 2,000 BTC. The overlap has only intensified fears that AI is becoming a force multiplier for attackers rather than just another tool in the security arsenal.

Read Entire Article