Boltz went dark on August 3. The non-custodial Bitcoin swap platform suspended indefinitely after months of relentless, AI-assisted attacks that kept arriving faster than developers could patch them. Attackers adapted their methods in days. The security team couldn't keep pace.

The company disclosed months of automated probing and several contained exploits that forced the shutdown. Boltz frames it plainly: they cannot safely reopen while under active assault and while security scans are still being reviewed. The suspected threat came from multiple resourceful groups, though the company offered no names or external confirmation of who's behind the waves.

The breakdown accelerated sharply in recent days. An August 1 notice flagged a bug in Boltz's Ethereum Virtual Machine integration, forcing the platform to initially disable swaps for USDT, USDC, WBTC, TBTC and RBTC while keeping Bitcoin, Lightning and Liquid operational. Two days later, everything stopped. No reopening timeline exists.

User funds stayed safe throughout. Boltz retained no custody of assets, so customers kept full control from start to finish. The operational losses, Boltz says, fell entirely on the company. Refund APIs remain live, and support staff are answering emails. Unilateral refunds work without needing Boltz infrastructure to cooperate.

The shutdown rippled outward. Bull Bitcoin, Aqua and ZEUS all reported service disruptions because they rely on Boltz's infrastructure to power their own offerings. The attack pattern matters here: this isn't a one-off breach. It's a sustained campaign that proved too expensive in engineering hours to defend against.

This article is informational and does not constitute financial or investment advice. Always conduct your own research before using any crypto service.