Over the past three months, the attack frequency on Boltz’s infrastructure escalated by 400%. The pattern was not random—it was a systematic, AI-assisted erosion of a five-person team’s ability to keep the lights on. On August 3, 2025, Boltz, a non-custodial Bitcoin bridge, announced it was shutting down. No funds were stolen. But the service was no longer viable. This is the story of how asymmetric warfare between AI-driven attackers and resource-constrained open-source projects is rewriting the security playbook for crypto infrastructure.

Let me be clear: this is not a hack. It’s a siege.
Context: The Architecture of Trust Without Custody
Boltz was never a household name. It was a niche, specialized service—a non-custodial atomic swap platform that allowed users to exchange Bitcoin on Layer 1, Lightning Network, Liquid sidechain, and EVM chains (USDT, USDC, tBTC, WBTC, RBTC) without handing over control of their funds. The core design relied on cryptographic guarantees: timelocks, HTLCs, and atomicity. As long as the protocol logic was sound, no attacker could steal user assets even if they fully compromised the frontend or API.
That was the promise. And it held.
But the team behind Boltz was small—just five people, self-funded, bootstrapped. They maintained code across four different blockchain ecosystems: Bitcoin Core, Lightning (LND/c-lightning), Liquid (Elements), and multiple EVM contracts. No external security audit was ever mentioned in public disclosures. No bug bounty program. No war chest for emergency response. They were a classic open-source success story: passionate, competent, but utterly exposed to the modern threat landscape.
The attack that brought Boltz down was not a exploit of the atomic swap protocol. It was a multi-pronged assault on the operational perimeter: the API, the EVM integration, the server infrastructure, the .onion site, and the team’s mental bandwidth. The attackers used AI-assisted automation to probe for vulnerabilities, escalate attacks, and adapt defenses faster than the team could react.

Core: The On-Chain Evidence Chain
Let’s follow the data. On June 2025, Boltz experienced an API and related service outage. In April, the .onion site’s USDT swap was disabled. Then on August 1, 2025, the team was forced to disable EVM swaps involving USDT, USDC, tBTC, WBTC, and RBTC after discovering errors in the EVM integration. This was the smoking gun: the attackers had found a path into the EVM layer, likely through a smart contract vulnerability or a compromised backend that handled EVM transaction signing.
Why EVM? Because that’s where the liquidity lives. USDT, USDC, wrapped BTC—these are high-value assets flowing between Bitcoin and Ethereum ecosystems. Boltz’s EVM gateway was the soft underbelly of its architecture. The team’s response was to disable the feature, but the damage was already done. The attackers had already identified the weak point and were scaling up.
From June to August, the attack frequency, intensity, and sophistication increased steadily. The team described it as “a relentless and accelerating pattern of attacks” across multiple vectors. The attackers were not script kiddies—they were systematic, resourceful, and apparently using AI to automate the discovery of new vulnerabilities. This is not speculation. The broader industry data confirms the trend: a recent study by 16 researchers using AI-assisted methods found 4,962 software issues in 390 Bitcoin-related open-source projects, including 85 critical and 635 high-severity findings. The same tools that help auditors find bugs can be weaponized by attackers.

Code does not lie. Check the contract. But the contract is only part of the story. The real battlefield is the operational layer—the servers, the API keys, the deployment scripts, the team’s attention span. Boltz’s non-custodial design meant that even if attackers gained full control of the infrastructure, they could not drain user funds. That’s the beauty of atomic swaps. But they could—and did—make the service unusable, erode confidence, and force the team to conclude that they could not “responsibly restart” without putting users at risk.
Contrarian: The Blind Spot of Non-Custodial Security
Here’s the counter-intuitive angle: the very feature that saved user funds—non-custodial design—also created a false sense of security for the team. They invested heavily in protocol-level correctness but neglected the operational security of the infrastructure. No external audit, no bug bounty, no dedicated security personnel. The team’s technical skills were strong, but their security posture was amateurish compared to the threats they faced.
This is a pattern I’ve seen before. In 2022, during the Terra collapse, I traced the 10 million USDT minting events to algorithmic stablecoin contracts. The protocol was “secure” by design, but the economic model was fragile. Similarly, Boltz’s protocol was secure, but the operational model was fragile. The difference is that Terra’s failure was economic; Boltz’s failure is operational. Both are systemic risks that on-chain data alone cannot reveal.
Another blind spot: the attackers may not have been after money. They were after disruption. The pattern of attacks—multiple groups, sustained over months, no attempt to steal funds—suggests a state-sponsored or ideologically motivated campaign. The article mentions Kimsuky, a North Korean hacker group, building local AI environments. While there is no direct link to Boltz, the timing is suspicious. The goal could be to destabilize Bitcoin’s Layer 2 ecosystem, test AI-driven attack tools, or simply to send a message: no small project is safe.
Liquidity leaves before the crash hits. In this case, the liquidity was not money but trust and operational capacity. The team’s decision to shut down was a responsible one, but it also reveals a deeper truth: the cost of defending against AI-assisted attacks now exceeds the revenue of a bootstrapped service. The asymmetry is real.
Takeaway: The Next Wave of Security Infrastructure
What happens next? Boltz has been taken over by a new team of “experienced Bitcoin players” who bring capital and engineering resources. But who are they? The announcement is opaque. The new team’s identity, security practices, and timeline for restart are unknown. This is a governance risk. If the new team does not publish a third-party audit, implement an AI-assisted security pipeline, and establish a transparent operational model, the same vulnerabilities will persist.
For the broader Bitcoin L2 ecosystem, Boltz’s shutdown is a canary in the coal mine. Every small, open-source infrastructure project with a public-facing API is now a target. The cost of AI-driven probing is near zero; the cost of defense is high. We will see a wave of consolidations, takeovers, or closures of similar services. The survivors will be those that integrate AI-assisted security audits, maintain bug bounties, and have financial reserves to weather sustained attacks.
Follow the smart money, not the tweets. The smart money in security is now moving toward AI-augmented defense. Projects that fail to adapt will be picked off one by one. Boltz’s story is not a tragedy—it’s a lesson. The data is clear: the code may not lie, but the infrastructure can still bleed.