Overview
- Boltz suspended all swap services on Aug. 3 and kept its API online only to support cooperative and unilateral refunds while providing no timetable to reopen.
- The company says no user funds were exposed because its atomic swaps use hash time‑locked contracts that let users retain control, and Boltz absorbed operational losses from contained exploits.
- Wallets that relied on Boltz for Lightning, Liquid and on‑chain conversions, including Aqua, Bull Bitcoin and ZEUS, have lost integrated swap functionality and are pursuing replacement options.
- Boltz described the incidents as months of automated, AI‑assisted probing by “multiple resourceful groups” but has not released technical indicators, a detailed vulnerability report, or an independent audit to confirm attribution.
- Observers say the case shows AI can speed vulnerability discovery beyond the patching capacity of small teams, a trend that could push projects to raise security budgets, outsource defenses, or consolidate toward larger providers unless shared defenses emerge.