Boltz Shuts Down: The AI Attack That Broke a Non-Custodial Bitcoin Bridge, but Not Your Funds

Partnerships | BitBlock |

The timestamp is August 3, 2025. The API is offline. The Swap requests are rejected. But the ledger remains clean.

Boltz Shuts Down: The AI Attack That Broke a Non-Custodial Bitcoin Bridge, but Not Your Funds

Boltz, a non-custodial Bitcoin bridge that once connected Bitcoin L1, Lightning Network, Liquid sidechain, and EVM chains, has shut down after what its founders described as “AI-assisted attacks” that escalated in frequency, intensity, and complexity over several months. The service is not dead—it’s being handed over to a new team with capital and engineering resources. But the story is less about a single project and more about a structural vulnerability that now threatens every small, open-source crypto infrastructure.

Boltz Shuts Down: The AI Attack That Broke a Non-Custodial Bitcoin Bridge, but Not Your Funds

Context: The Bridge That Trusted Nobody

Boltz was not a custodian. It used atomic swaps—timelock-based, trustless swaps—to exchange Bitcoin for Lightning Network invoices, Liquid assets, or EVM-based tokens like USDT, USDC, tBTC, WBTC, and RBTC. The model was pure: users controlled their private keys at all times. The service was just a liquidity coordinator and UX layer. The team was small—five people, self-funded, no token, no VC. They operated on a fee-for-service model, covering server costs and salaries.

The protocol had been running for years. It was a niche but vital piece of infrastructure for Bitcoin maximalists who wanted to move into the Lightning ecosystem or interact with DeFi on Ethereum without trusting a centralized exchange. The code was open source. The security model was layered: the protocol layer (atomic swaps) protected user funds; the infrastructure layer (APIs, frontend, EVM integration) protected service availability.

Boltz Shuts Down: The AI Attack That Broke a Non-Custodial Bitcoin Bridge, but Not Your Funds

Core: The On-Chain Evidence Chain

Let the data speak. The attack timeline, as disclosed by the team, reveals a coordinated, multi-vector siege:

  • April 2025: First disruptions. The .onion site’s USDT swap was disabled. The team attributed it to “ongoing attacks.”
  • June 2025: API and related services experienced downtime. The team scrambled to patch.
  • August 1, 2025: Boltz disabled EVM swaps involving USDT, USDC, tBTC, WBTC, and RBTC after discovering a bug in the EVM integration. This was the critical weakness: the EVM layer was the gap between Bitcoin’s trustless world and the smart-contract complexity of Ethereum.
  • August 3, 2025: Full shutdown. The team publicly stated they could not “responsibly resume” operations because “multiple groups seemed to be systematically targeting Boltz’s infrastructure.” The attack cluster had accelerated in the final weeks, showing “steady, automated, AI-assisted probing.”

The key metric: no user funds were lost. The atomic swap protocol held. The non-custodial design meant that even if the attackers owned the API, they could not sign transactions on behalf of users. The ledger does not lie, only the storytellers do. Here, the storyteller is the attack itself: a persistent, resourceful adversary that didn’t want the money—it wanted to destroy the service.

Contrarian: AI Attacks Are a Double-Edged Sword

The conventional narrative is that AI is the enemy. But the data from the same week shows a different picture. A separate study by 16 researchers using AI-assisted methods found 4,962 software issues in 390 Bitcoin-related open-source projects, including 85 critical and 635 high-severity findings. The same AI that can probe Boltz’s EVM integration can also audit code at scale.

The real story is not “AI is stealing our funds.” It’s that the cost of attack has dropped below the cost of defense for small teams. Boltz’s five-person team, covering Bitcoin core, Lightning implementations, Liquid sidechain, and EVM smart contracts, simply could not keep up with a 24/7 automated adversary. They had no security budget, no bug bounty, no external audit. The asymmetry is brutal.

But here’s the contrarian insight: the Boltz shutdown is a net positive for the ecosystem. It proves that non-custodial designs can survive a determined attack without losing user assets. It also forces the industry to face the reality that “open-source” does not mean “safe by default.” The new team, described as “experienced Bitcoiners with capital and engineering resources,” will likely perform a full code audit, rebuild infrastructure, and implement AI-assisted defense. Precision is the only hedge against chaos.

Takeaway: The Next Week Signal

Boltz will probably return. The question is whether the new team will make the same mistakes. The market will vote with liquidity: if swaps resume with a clean audit and transparent governance, trust will rebuild. If not, users will migrate to Thorchain, tBTC, or other non-custodial alternatives.

The broader signal is clearer: small open-source infrastructure projects are now in a structural arms race. AI-assisted attacks are not a future threat—they are the current reality. Every project that lacks a dedicated security team, a bug bounty, and an AI-assisted code review pipeline is a target. The days of a five-person team running a multi-chain bridge are over.

I follow the bytes, not the headlines. The bytes show that Boltz’s protocol did its job. The infrastructure did not. The next phase will test whether the new controllers can close that gap. If they can, the story becomes a lesson. If they can’t, it becomes a warning.