Incident case file
Sign in to watchBoltz Bitcoin Bridge — AI-Assisted Attack Suspension
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatIn the weeks leading up to August 3, 2026: Boltz, a non-custodial Bitcoin bridge enabling atomic swaps between on-chain Bitcoin, the Lightning Network, and the Liquid sidechain via Hashed Time-Locked Contracts (HTLCs), observes a steady and escalating pattern of automated, AI-assisted probing directed at its open-source infrastructure. In Boltz's own words: 'Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.' August 3, 2026 (early morning): Boltz takes its entire system offline, suspending both its Bitcoin/Lightning and EVM-side swap services in full. No user funds are lost as a result — Boltz's non-custodial architecture means the platform never directly holds customer funds — but the company privately acknowledges internally absorbing the financial cost of 'the attacks that did get through,' without publicly disclosing a specific dollar figure for these losses. August 4, 2026: Boltz restores its Bitcoin and Lightning Network swap services, but its EVM-side (Ethereum-compatible chains) swap functionality remains suspended pending further internal security review. The suspension produces significant downstream effects across multiple partner wallets and services that depend on Boltz's underlying swap infrastructure, including AQUA (developed by JAN3), Bull Bitcoin, ZEUS Wallet, Blockstream, and Cake Wallet — several of which announce their own related Lightning or Liquid service disruptions as a direct consequence. Some media coverage (notably from Protos) speculates, without providing confirmed evidence, about whether the suspension might also relate to broader external regulatory or governmental pressures; Boltz itself has not substantiated or commented on any such claim. As of the close of the reporting window, EVM-side swap functionality has not been restored, and no attacker identity, detailed exploit technical breakdown, or precise internal financial impact figure has been publicly disclosed by Boltz.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)