Non-custodial bridge Boltz has suspended swaps indefinitely: AI-assisted attacks arrive faster than the team can defend against them. In response, the Bitcoin Red Team coordinated by Calle has already scanned 390 repositories with AI agents, filing nearly 5,000 reports in 27 hours.
Boltz, one of the most widely used non-custodial bridges for moving bitcoin between the mainchain, Lightning Network and Liquid, has suspended its swaps indefinitely. In a thread on X the team explained that the decision does not stem from a single incident: for months the infrastructure has faced a steady increase in “AI-assisted automated probing”, with several exploits contained one by one. In recent days the pace accelerated sharply and, after reviewing the results of its own security scans, the team concluded it could not responsibly reactivate the service.
Attackers “are now iterating faster than a team of our size can find and fix,” Boltz writes, describing being targeted by multiple well-resourced groups while racing to deploy patches. The API remains active for cooperative refunds, and unilateral refunds continue to work because they do not depend on Boltz infrastructure. “No user funds were ever at risk,” the team stresses: the protocol is non-custodial by design and the losses, for a fully bootstrapped company, were its own.
Boltz describes this explicitly as a “paradigm shift for Bitcoin services operating on open-source stacks.” It is a picture of a new problem: when the attacker is an agent that never sleeps, a human defender working human hours starts at a disadvantage.
The ecosystem’s response came quickly and uses the same tool. The Bitcoin Red Team coordinated by Calle and funded by OpenSats – the developer known for the ecash protocol Cashu – has grown to 16 people distributed globally, working around the clock on a large-scale security audit of Bitcoin codebases. The figures after 27.5 hours, published on X: 4,962 reports across 390 projects, of which 85 critical and 635 high-severity, at a rate of 2.31 critical findings per person per hour.
The approach reverses the asymmetry: if AI agents can find vulnerabilities at machine speed for attackers, they can do the same for defenders, scanning open-source repositories before flaws are exploited. The Red Team’s reports are sent via private disclosure to project maintainers, with the aim of patching before others can take advantage.
The Boltz case is a warning for every small, open-source Bitcoin service: the race between attack and defence now plays out at inference speed, and those who cannot afford a permanent red team risk finding that out at their own expense.





