Non-custodial service unable to match pace of automated attacks

Boltz, a non-custodial Bitcoin swap service, announced on August 3 that it is shutting down swaps after months of AI-assisted automated probing led to contained exploits and mounting losses the team could no longer defend against.

“Boltz said automated, AI-assisted probing led to several contained exploits before the attack accelerated sharply,” according to the service’s statement. “Boltz said its team could no longer keep pace, so swaps will remain offline until further notice.”

The service bridged Bitcoin layers by switching between on-chain BTC, Lightning Network, and Liquid. Its non-custodial design kept user funds safe throughout the attacks; users retained control of coins and had built-in refund paths. Boltz absorbed exploit losses on its own books rather than exposing customers to the breach.

The two-front security problem for small teams

Boltz’s shutdown reflects a broader vulnerability in crypto infrastructure. Small teams face simultaneous pressure from real automated exploit attempts and floods of low-quality automated reports that consume maintainer time. Staying secure requires continuous automated testing, a large triage team, a fast patch-release process, round-the-clock monitoring, external audits, bug bounties, and the ability to shut down broken components without taking down the entire product.

The scale of AI-enabled exploitation is measurable. Anthropic analyzed 832 accounts banned for AI-enabled cyber activity between March 2025 and March 2026. In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) told federal agencies that AI is helping researchers and attackers find flaws at a similar pace, pushing the riskiest vulnerabilities toward patch windows measured in days.

Crypto infrastructure under pressure

Crypto infrastructure took significant losses in the first half of 2026. TRM Labs and CertiK analyzed hack losses during that period. According to TRM Labs, 76% of crypto hack losses came from infrastructure and operational compromises. CertiK documented $444 million stolen across 33 wallet compromise incidents in H1 2026.

The security challenge extends beyond crypto. Google’s Chrome browser uses automated triage to filter noise, reproduce bugs, and route issues; the company estimated this process saves hundreds of developer hours monthly. Large language models generate candidate fixes for most Chrome vulnerabilities, with separate AI agents reviewing work and writing tests before human sign-off.

The Open Source Security Foundation is building tools to triage and validate AI-generated vulnerability reports. OpenJS warned that floods of low-quality AI-written reports consume maintainer time, creating a secondary cost burden for maintainers already stretched thin.

Boltz did not specify when it expects to resume swaps or under what conditions service might return.