Bitcoin Protocol Boltz Halts Swaps Amid AI-Assisted Cyber Attacks

iconCoinpedia
Share
AI summary iconSummary
Boltz, a Bitcoin atomic swap protocol, has halted swap services due to AI-assisted cyber attacks. The protocol update took effect at 5:54 a.m. ET, impacting Lightning and Liquid swaps. Attackers are using AI to exploit infrastructure faster than the team can respond. Users’ funds remain safe thanks to Boltz’s non-custodial model. The API is still active, processing refunds. This follows a prior protocol update in August that paused EVM swaps. AI + crypto news continues to highlight rising threats in the space. Wallets like Bitcoin Bull and Aqua are collaborating to restore services.

Boltz, the most dominant Bitcoin atomic swap and bridge protocol, has suspended its swap services indefinitely, citing a wave of sophisticated AI-assisted exploits.

Attempted Bitcoin Exploit at Boltz

The halt began at 5.54 a.m ET, with the Lightning and Liquid swap rails cut off from wallets such as Aqua and Bitcoin Bull. In a statement issued about six hours later, the Boltz team explained:

“Over the past months we have seen a steady rise in automated, AI-assisted probing of our infrastructure, and we have dealt with several exploits. Each was contained, but the pattern is clear: attackers now iterate faster than a team our size can find and patch.”

In addition, the team noted that the attacks appeared to originate from “resourceful groups,” and that it could not “responsibly re-enable Boltz swaps.”

According to Boltz, users’ Bitcoin remains secure due to its non-custodial design, and operational costs were absorbed internally. Currently, the protocol’s API remains online, conducting refunds of incoming swaps.

Attack history

On August 1, Bolts halted its Ethereum Virtual Machine (EVM) swaps, citing an EVM integration bug. The latest attack focused away from EVM and onto the Bitcoin ecosystem.

Similar attacks took place recently: the Metronome synthetic asset shortfall of July 31, where an embedded oracle delay led to the loss of about $16 million. Another was the August 1 Adform script poisoning, which interfered with the wallet address copy-paste feature.

A most prominent attack is the recent Coldcard firmware vulnerability that has so far drained $116 million in Bitcoin.

Of the Boltz attacks, Lucas Ferreira of the Bitcoin non-profit Vinteum noted:

“Boltz has a brilliant team, but it’s a small team facing increasingly sophisticated, AI-powered groups of hackers.”

Wallet reaction

Francis Pouliot, CEO of Bull Bitcoin, said the company was working to restore the impaired swap capabilities. Samson Mow, CEO of JAN3, the firm behind the Aqua wallet, said its team was working with Boltz to restore functionality to optimal levels. Meanwhile, Lightning wallet ZEUS posted that it would be offline due to Boltz downtime.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.