Boltz, the non-custodial bridge that lets users swap between Bitcoin’s mainchain, the Lightning Network, and the Liquid sidechain, pulled the plug on its services indefinitely on August 3. The reason: months of automated, AI-assisted attacks on its infrastructure that the small team simply couldn’t patch fast enough.
No user funds were compromised, thanks to the platform’s non-custodial architecture built on hash time-locked contracts. But the company itself absorbed losses from contained exploits, and the shutdown ripples outward to every wallet and service that relied on Boltz as plumbing for cross-layer Bitcoin transactions.
What happened and who’s affected
The attacks reportedly escalated throughout July and into early August, with a sharp spike in the days just before the shutdown announcement. Boltz described the situation as a “major paradigm shift” for open-source Bitcoin services, a phrase that suggests the team doesn’t expect a quick return.
The immediate casualties of the suspension include Aqua and Bull Bitcoin, two wallets that integrated Boltz’s swap functionality to give users seamless transitions between Lightning and Liquid. Those users now need to find alternative routes for cross-layer transactions.
Boltz is a fully bootstrapped operation, meaning there’s no venture capital war chest to fall back on when things go sideways. The losses from the exploits, while contained enough to protect users, still hit a self-funded team where it hurts most: the operating budget that keeps the lights on and the code shipping.
AI-powered attacks: a new threat vector
For open-source projects specifically, the threat is amplified. Their codebases are public by design, which is normally a feature, not a bug. More eyes on the code means more people catching vulnerabilities. But when AI can scan those same public codebases and generate exploit strategies at machine speed, the equation flips. The transparency that makes open-source trustworthy also makes it a richer target for automated reconnaissance.
A rough week for Bitcoin security
Boltz’s shutdown didn’t happen in a vacuum. The same week saw a major Coldcard hardware wallet exploit that reportedly drained an estimated $114 million from user accounts starting around July 30. Two significant Bitcoin-layer security incidents in the span of a few days is the kind of coincidence that makes the entire ecosystem nervous.
Boltz’s non-custodial design protected users from direct fund loss in this case, which is a meaningful distinction. But the operational disruption is real and consequential.
What this means for investors and Bitcoin layer users
For anyone who relied on Boltz for regular swaps between Lightning and Liquid, the immediate task is finding alternatives. Boltz carved out a niche precisely because few other services offered the same combination of non-custodial security and cross-layer flexibility.
Boltz was a single point of failure for several significant wallets, including Aqua and Bull Bitcoin, and that dependency just got exposed.
The silver lining, if you can call it that, is that Boltz’s non-custodial architecture worked exactly as designed. User funds stayed safe even as the platform itself was compromised. That’s a strong argument for the hash time-locked contract model and for non-custodial design principles generally.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
22









English (US) ·