Boltz Bitcoin bridge shuts down after AI-assisted security attacks

Editorial illustration for: Boltz's shutdown exposes the real cost of AI-powered attacks on crypto teams

In brief

  • Boltz announced August 3 that AI-assisted probing triggered multiple contained exploits before attacks accelerated sharply.
  • Non-custodial design protected user funds throughout, but operational burden of sustained attacks became unsustainable.
  • Infrastructure compromises now account for 76% of crypto hack losses, forcing smaller teams to merge or shut down.

The attack surface grows faster than defenses

Boltz bridged Bitcoin's layers by switching between on-chain BTC, the Lightning Network, and Liquid. Its non-custodial structure meant users retained control of their coins throughout each swap, with a built-in refund path if anything went wrong before settlement. Boltz absorbed the losses from exploits on its own books before deciding the swap product could no longer operate safely.

The shutdown reflects a broader shift in how attackers work. Anthropic analyzed 832 accounts banned for AI-enabled cyber activity between March 2025 and March 2026, finding attackers increasingly relying on AI to scan targets and collect data. Google's Threat Intelligence Group described the same move toward industrial-scale use of generative models in offensive workflows. CISA moved in June to tell federal agencies that AI is helping researchers and attackers find flaws at a similar pace, then pushed the riskiest vulnerabilities toward patch windows measured in days.

Small teams end up fighting on two fronts at once: real automated exploit attempts and automated noise that eats the attention needed to catch them. Staying safe now requires continuous automated testing, a team large enough to triage findings, and a fast, safe patch-release process. Teams also need round-the-clock monitoring, external audits, bug bounties, and the ability to shut down one broken component without taking down the whole product.

The cost of staying independent

Smaller teams facing security costs have options including raising money for security, outsourcing it, merging with a larger provider, narrowing offerings, or shutting down a product. Boltz chose to shut down rather than compromise on user control.

The economics are stark. TRM Labs found that infrastructure and operational compromises accounted for roughly 76% of crypto hack losses in the first half of 2026, even though these attacks represented only about 15% of incidents. CertiK identified wallet compromise as the costliest category over the same period, with more than $444 million stolen across 33 incidents.

The pattern is clear: defending a non-custodial product against AI-assisted attacks demands resources that smaller teams don't have. When the cost of staying independent exceeds what a team can bear, consolidation follows. Users end up with fewer choices and more reliance on large custodians—the opposite of what crypto was built to enable.