Security news

Showing 201–250 of 341
Clear filters

August 18, 2026

Security

BitBox fixes two severe hardware wallet flaws in BitBox02 and Nova

BitBox patches two severe hardware wallet vulnerabilities BitBox has released a firmware update for BitBox02 and BitBox02 Nova fixing two severe flaws: one that could have let a malicious host install firmware on unconfigured Multi editions, and another in Silent Payments that could have locked Bitcoin to an unintended address. The company said neither issue was exploited and no user funds were reported lost.

Security

Three August Crypto Data Breaches Exposed 253,487 Customers in Four Days

Three crypto customer data breaches expose 253,487 users in four days SafePal, Trezor and Israeli broker Bits of Gold disclosed breaches between Aug. 13 and Aug. 16 that exposed a combined 253,487 customers’ names, phone numbers, addresses and purchase data. Trezor’s ShipMonk breach and Bits of Gold’s roughly 200,000-user breach were both tied to Metabase flaw CVE-2026-72898, while SafePal said a third-party order tracking plugin exposed 39,798 records. No keys or funds were stolen.

Security

Wallet Linked to 2022 Pando Rings Hack Moves ETH to Tornado Cash Again

Pando Rings exploiter swaps $3M DAI for ETH, sends 800 ETH to Tornado Cash A wallet tied to the 2022 Pando Rings oracle hack reactivated on Aug. 18 after two months of inactivity, swapping 3 million DAI for about 1,570 ETH via CoW Protocol, Onchain Lens reported. Around 800 ETH worth roughly $1.52 million was then sent to Tornado Cash in eight transactions, moving funds still traceable to the original exploit.

Security

Harmony to Rewind Chain After Exploit Minted 2.385 Trillion ONE

Harmony Protocol to roll back network after 2.385 trillion ONE exploit Harmony developers said they will rewind the chain to Aug. 11 after an Aug. 12 exploit let an attacker mint and transfer 2.385 trillion ONE through flaws in cross-shard receipt validation and quorum verification. The rollback will reset Shard 0 and Shard 1 to pre-breach checkpoints, discarding 141,628 blocks on Shard 0 as well as 109,126 user transactions and 315 staking transactions.

August 17, 2026

Security

Fake The Odyssey Pirated Downloads Used to Spread Lumma Stealer, Bitdefender Warns

Bitdefender warns fake Odyssey rips are spreading Lumma Stealer Bitdefender said fake pirated downloads of The Odyssey are circulating as supposed WEBRip and Blu-ray files but are actually Windows executables that install Lumma Stealer, malware that targets crypto wallets, browser passwords, payment data and remote desktop credentials. The malware also steals authentication cookies, which can let attackers hijack accounts even when MFA is enabled.

Security

Harmony proposes Aug. 11 rollback to remove forged ONE after network incident

Harmony proposes Aug. 11 rollback after forged ONE mint Harmony plans to restart its blockchain from two Aug. 11 checkpoints to remove ONE created in a forged mint, discarding all later activity including 109,126 regular transactions and 315 staking transactions. The network said validators would resume from shard 0 block 92,730,035 and shard 1 block 94,978,279, using replacement databases and client v2026.1.2 to reject the abnormal block hashes tied to the incident.

Security

BitMart shutdown faces pressure over frozen withdrawals and unpaid wage claims

BitMart shutdown draws scrutiny over frozen withdrawals and unpaid staff BitMart is facing fresh criticism as users report they still cannot withdraw funds and employees say their final month’s salary and compensation remain unpaid, even as the exchange says it is preparing an “orderly” shutdown. The company promised proof of reserves on May 23 but has yet to publish it; spot and futures trading are set to end on Aug. 26, with full closure scheduled for Jan. 31, 2027.

Security

Galaxy Research says Coldcard-related Bitcoin losses have exceeded $115 million

Galaxy: Coldcard losses top $115M as 1,778.58 BTC swept from 8,680 addresses Galaxy Research said Coldcard-related losses have reached more than $115 million, covering 1,778.58 BTC swept from 8,680 addresses since July 30 in data through Aug. 13. The firm said none of the stolen coins predate Coldcard’s March 17, 2021 firmware release, while the biggest sweep wave took about $70.2 million, or 61% of the total, draining 1,195 addresses in 41 minutes across nine blocks.

Security

Study Estimates $575 Million Lost to Address Misuse on Ethereum and BNB Chain

USENIX-backed study links address mistakes to $575M in ETH and BNB losses Researchers from Sun Yat-sen University, Peking University and Zhejiang University said on-chain analysis of millions of Ethereum and BNB Chain addresses found 65,340 high-risk cases of “address misuse” tied to testnet addresses, reused contracts and wallets with exposed private keys. The study estimates losses of about $575 million, including 104,245 ETH and 9,045 BNB sent to compromised wallets and 22,738 ETH plus 8,681 BNB sent to the wrong contract type.

Security

Apple fixes Mac screen-sharing bug exploited to install Monero miners

Apple patches Mac screen-sharing flaw used to install Monero miners Hackers exploited a pre-authentication flaw in Apple’s Mac screen-sharing feature to take full control of multiple internet-exposed Macs and covertly install Monero mining software, the Netherlands’ National Cyber Security Centre said. Apple fixed the bug on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and Microsoft researchers urged users to update immediately.

August 16, 2026

Security

SafePal says 39,798 customer orders were exposed in access-control breach

SafePal says nearly 39,800 customer orders exposed in security incident SafePal said an access-control flaw exposed order data for about 39,798 customers who placed orders between March 2 and April 11, including names, contact details, shipping addresses and purchase information. The company said seed phrases, private keys, wallet passwords and funds were not exposed, the flaw has been fixed, and affected users were notified as SafePal warned of phishing attempts using the stolen order details.

Security

Bits of Gold investigates third-party breach that may have exposed customer data

Bits of Gold probes third-party breach exposing customer data Israel-regulated crypto broker Bits of Gold said a cyber incident tied to a third-party support and analytics system may have exposed customer names, ID numbers, emails, phone numbers, IPs, bank account details and public wallet addresses. The company said customer funds, crypto, passwords, ID scans and full card details were not affected, and it has blocked access, disconnected the system and notified authorities.

August 15, 2026

Security

Sherlock Audit Found 96 XRPL Bugs Before Proposed Features Reached Mainnet

Sherlock audit finds 2 critical XRPL bugs before mainnet activation Ripple’s two-week Sherlock audit contest uncovered 96 valid vulnerabilities in five proposed XRP Ledger amendments, including two critical flaws that could have drained accounts without private keys or silently burned XRP through repeated fee charges. Ripple paid $309,000 from a $550,000 RLUSD prize pool, and both affected features were rewritten and shipped in xrpld 3.3.0 on Aug. 6 without being activated on mainnet.

Security

French Tax Agency Says 678,438 Taxpayers Were Exposed in Data Breach

French tax agency confirms data breach affecting 678,438 taxpayers France’s General Directorate of Public Finances said threat actors accessed and extracted addresses and real estate data tied to 678,438 taxpayers after compromising internal servers, with access cut off on June 12. The agency said login data was not exposed and it will notify affected people next week, while French crypto holders warned the leak could raise the risk of targeted “wrench attacks.”

August 14, 2026

Security

Galaxy: Confirmed Coldcard Bitcoin Theft Losses Exceed 1,778 BTC

Galaxy says Coldcard exploit thefts top 1,778 BTC Galaxy Research said the Coldcard seed-recreation exploit has now drained more than 1,778 BTC, about $112 million, from confirmed owner-attributed thefts since July 30, and warned the final figure will likely be higher. The firm said no confirmed attack activity has appeared after Aug. 6, likely because vulnerable holders migrated or most funds were already drained, but 1,531 BTC remains parked in attacker-controlled addresses.

Security

Singapore says fake crypto job scams and system breaches caused $11.8 million in losses

Singapore warns of $11.8M fake job scam targeting crypto and tech firms Singapore police and cyber agencies said a scam built around fake job offers and compromised software systems caused $11.8 million in losses. In one case, a LinkedIn approach led a victim to run malware in a bogus coding test on a company device; it stole a session token, bypassed MFA, accessed a Bitbucket code repository, and helped attackers alter internal systems and move funds by evading transaction and approval checks.

Security

Google Suspends Advertiser After Reported $550,000 Hyperliquid Phishing Loss

Google suspends advertiser after reported $550,000 Hyperliquid phishing loss A Hyperliquid user appears to have lost about 550,019 USDC on Aug. 13 after interacting with a phishing site allegedly promoted through a Google search ad, based on on-chain transfers flagged by FlashRescue co-founder Darcy. Google said it suspended the advertiser tied to the campaign, while available evidence does not indicate any breach of Hyperliquid’s blockchain or trading protocol.

August 13, 2026

Security

Trezor says ShipMonk breach exposed order data for about 13,700 customers

Trezor data breach exposes details of nearly 13,700 customers Trezor said a breach at shipping partner ShipMonk exposed customer order data for about 13,700 users across seven countries after an unauthorized party accessed ShipMonk systems. The leaked data included names, emails, phone numbers and shipping addresses for 11,742 customers, while 1,947 others had names, cities and emails exposed; Trezor said its internal systems and hardware wallets were not compromised.

Security

Six npm Packages Used Ethereum Wallet Data to Conceal Malware Control Servers

Sonatype flags six npm packages using Ethereum wallet to hide malware C2 Sonatype Research Labs said six npm packages used an attacker’s Ethereum wallet to fetch command-and-control server addresses, including three compromised real libraries: @kolbo/mcp@1.57.1, agentgui@1.0.1127 and godot-kit@1.0.1786316795. The same payload also appeared in envpack-conf@1.0.1, postcss-initial-provider@3.0.4 and tailwindcss-motion-advanced@1.0.1; Sonatype urged anyone who installed them to remove the packages and check for second-stage code execution.

Security

Trezor says shipping partner breach exposed some customer addresses and phone numbers

Trezor warns customer data leaked in third-party shipping breach Trezor said a third-party shipping partner exposed some customer phone numbers and shipping addresses, while its own systems, devices, private keys and wallet backups were not compromised. The company said only customers who received notification emails were affected, with the impact limited by a policy requiring partners to delete or anonymize order data 90 days after delivery. It is now accelerating an Anonymous Delivery option in the EU by September and in the US by year-end.

Security

Researchers Detail 'Zoomsday' Zoom Flaws That Enabled Zero-Click Meeting Takeovers

Researchers disclose Zoom flaws that enabled zero-click device takeover in meetings Israeli cybersecurity firm A Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working “Zoomsday” exploit in under 24 hours, allowing code execution on another participant’s device with no click, download or approval. Zoom released fixes between June 22 and July 20, but users on older app versions still need to update because server-side protections cannot fully stop the attack in end-to-end encrypted meetings.

August 12, 2026

Security

Boltz founders step down as unnamed Bitcoin group moves to take over suspended swap service

Boltz founders exit as veteran Bitcoiners take over suspended swap service Boltz said all original founders stepped down effective immediately and an unnamed group of “veteran Bitcoiners” will take over the suspended Bitcoin swap service, providing capital and engineering resources while vulnerabilities are fixed. Swaps remain offline after Aug. 3 attacks that Boltz said grew in frequency and sophistication and caused losses, though it added user funds were never at risk because the service is non-custodial.

Security

Malwarebytes Finds $500 Fake Tesla Token Presale Kit Built to Drain Crypto Wallets

Malwarebytes spots $500 kit for fake Tesla token presale scam Malwarebytes said a cybercrime forum seller known as xrep is offering a $500 “scam-in-a-box” that lets low-skill operators launch a fake $TSLA presale using Tesla branding and X account details. The kit includes phishing pages, a fake dashboard and a control panel that can collect 12-word recovery phrases, log usernames and locations, and prompt victims to send BTC, ETH, USDT or DOGE to attacker-controlled addresses.

Security

Ledger Executive Says Coldcard Breach Exposed Weak Randomness, Not Hardware Wallets

Ledger exec says Coldcard hack shows weak randomness, not hardware wallet risk Ledger’s Chief Human Agency Officer Ian Rogers told Bloomberg the $116 million Coldcard hack was caused by a 2021 firmware bug that sent seed generation through a software pseudorandom number generator instead of the hardware chip, leaving just 40 to 72 bits of entropy for attackers to brute-force. TRM Labs traced 1,082 BTC drained in the first 41-minute sweep on July 30; Rogers said AI is accelerating this kind of exploit and broader attacks on secrets and code.

Security

Ravencoin Hits Record Low as Consensus Flaw Forces Competing Chain Response

Ravencoin drops to record low after consensus exploit hits mainnet RVN fell as much as 22% to $0.002754 after a consensus vulnerability let vulnerable Ravencoin nodes accept invalid blocks from block 4,487,776. Mining pools 2Miners and RavenMiner are building a competing chain that would exclude blocks after 4,487,775, a move that could force a roughly three-day reorganization and reverse later transactions. Upbit and Bitget suspended RVN deposits and withdrawals, while Upbit kept trading open.

August 11, 2026

Security

Coreum Bridge Exploit Drains 199,916 XRP After Deposit Check Failure

Coreum bridge exploit drains 199,916 XRP in 97 minutes Coreum’s cross-chain bridge lost 199,916 XRP on Aug. 9 after an attacker exploited a deposit verification flaw to trigger withdrawals without making real deposits. XRPL.io shows the bridge sent 94 XRP payments approved by 17 of 28 relayer keys, with the funds moved to two newly created wallets, leaving the bridge with 493.5 XRP.

Security

Address Poisoning Scam Sends $100K in USDT to Lookalike Wallet

User loses $100K in USDT to address poisoning scam A crypto user sent about 100,000 USDT to a lookalike wallet address that an attacker had planted in the victim’s transaction history 66 days earlier, Cyvers Alerts said on Aug. 11. Cyvers said the attacker later swapped the stolen funds for about 52.8 ETH, in what it described as a social-engineering attack that relied on the victim selecting a forged address from history rather than a flaw in Tether, Ethereum, or the wallet software.

Security

Coldcard hack loss estimates range from 1,432 BTC floor to about 1,816 BTC

Coldcard hack loss estimate ranges from 1,432 BTC to about 1,816 BTC Investigators still have no definitive loss figure for the Coldcard hack, with estimates diverging because the theft hit self-custody wallets and relies on victim reports plus on-chain tracing. CryptoQuant has confirmed 1,432 BTC as a floor, while Galaxy Research puts its high-confidence minimum at 1,730 BTC and TRM Labs estimates about 1,816 BTC from more than 5,200 addresses, saying the total could keep rising as more victims come forward.

Security

Coreum XRPL Bridge Lost 199,916 XRP in Suspected Relayer Logic Exploit

Coreum XRPL bridge drained of nearly 200,000 XRP in relayer logic exploit On-chain analysis says 199,916.3 XRP was drained from Coreum’s XRPL bridge on Aug. 9 after relayers treated attacker self-payments with bridge memos as valid deposits and signed 94 withdrawals over 97 minutes. The evidence points to a destination-check flaw in relayer code, not stolen keys or an XRP Ledger failure; the bridge remains halted and Coreum had not published an official incident report by Aug. 11.

Security

BTCPay supporters offer up to 3 BTC bounty after Lightning wallet exploit

BTCPay backers offer up to 3 BTC bounty after Lightning wallet exploit BTCPay Server supporters pledged a bounty worth 10% of any recovered stolen funds, capped at 3 BTC, after a critical flaw in versions before 2.4.2 was actively exploited. BTCPay said attackers could steal LND admin macaroon credentials and take control of connected Lightning wallets, while onchain wallets were not affected, and urged users to upgrade to 2.4.2 or shut down servers and rotate credentials.

August 10, 2026

Security

Crypto Projects Lost About $110M in July as 2026 Hack Count Nears Record Pace

Immunefi says 2026 is on pace for a record year of major crypto hacks Crypto projects lost about $110 million to hacks in July, and Immunefi said 2026 could surpass 2024’s record for major incidents. The platform has logged 164 hacks through Aug. 3, including 67 losses above $1 million, and projects that figure could reach 114 by year-end versus the previous record of 72. Immunefi also said audit competitions found 6.2 serious flaws per engagement on average, compared with 1.5 in private tier-1 audits.

Security

Coinsbuy Wallets Reportedly Drained of $7.9 Million Across Ethereum and Tron

Coinsbuy reports $7.9M theft from Ethereum and Tron wallets Wallets linked to crypto payments platform Coinsbuy were reportedly drained of more than $7.9 million across Ethereum and Tron at around 13:00 UTC, in an incident first flagged by blockchain investigator Specter Analyst. Coinsbuy briefly paused deposits and withdrawals, then resumed services; the attacker was reportedly moving funds through exchanges into Monero, while ChangeNOW froze a six-figure amount tied to the theft.

August 9, 2026

Security

Crypto Thefts Reached $3.4 Billion in 2025 as Investigators Face a 45-Day Recovery Window

Crypto theft hit $3.4B in 2025, topped $1B again in H1 2026 Hackers stole about $3.4 billion in crypto in 2025 and another $1.1 billion across 212 incidents in the first half of 2026, with Lazarus-linked groups blamed for roughly 55% of this year’s losses. Investigators have about 45 days before laundering through DeFi, mixers, bridges and low-KYC venues makes recovery unlikely; less than 5% of the $1.5 billion Bybit hack was recovered.

Security

BTCPay blocks remote LND access on Docker after credential theft attacks

BTCPay restricts remote LND access after critical credential theft flaw BTCPay Server has temporarily blocked public remote connections to LND nodes on Docker deployments after attackers exploited a critical flaw to steal macaroon credentials and move funds. Version 2.4.2 installs LND 0.21.1 and auto-rotates credentials on standard setups, but operators using their own reverse proxy, Tor service or port forwarding must rotate them separately; Foundation and Citadel21 both reported drained Lightning nodes.

August 8, 2026

Security

BTCPay Server issues emergency fix for exploited 2FA bypass in merchant payment software

BTCPay Server ships emergency patch for exploited 2FA bypass bug BTCPay Server has released v2.4.2 after disclosing a critical vulnerability under active exploitation that let attackers bypass TOTP two-factor authentication via Greenfield API Basic Authentication. The flaw affected BTCPay’s application layer, not Bitcoin, and BTCPay urged operators to upgrade immediately, update NBXplorer to v2.6.10, and use scoped API keys instead of Basic Authentication.

August 7, 2026

Security

HTX Reserve Funds Were Moved to Poloniex-Labeled Wallets After Sanctions, Report Says

HTX reserves moved to Poloniex-labeled wallets after sanctions, report says After EU and UK sanctions on HTX, TRM Labs said the exchange began rapidly rotating on-chain addresses and shifted $1.3 billion in reserves into an undisclosed “ThirdParty” category in its proof-of-reserves. Protos traced 71,853.22 stETH, about $135 million, from HTX’s May 1 reserve address through several wallets on May 30 to addresses labeled on Etherscan as Poloniex, suggesting HTX funds were commingled with Poloniex reserves.

Security

Trezor Flags Sponsored Google Phishing Results After User Reports Major Loss

Trezor warns of phishing sites in sponsored Google results Trezor said on Aug. 7 it is seeing more phishing websites impersonating the company, including some appearing in sponsored Google search results, after X user David (@ReallyBadDay99) claimed he lost his “life savings” by clicking a top sponsored result for “Trezor wallet.” Trezor did not confirm the loss, but warned users never to enter a wallet backup on any website and to verify they are on its official site.

Security

BTCPay Server urges immediate update to v2.4.2 over actively exploited flaw

BTCPay Server urges emergency update to v2.4.2 over active exploit BTCPay Server told users to install version 2.4.2 immediately after finding a critical vulnerability that is already being actively exploited and could lead to stolen funds. The project said operators who cannot update right away should shut down their servers, but it has not disclosed which earlier versions are affected, how the attacks work, or whether losses have been confirmed.

Security

Coldcard Exploit Drives July Crypto Theft Losses to $247.4 Million

July crypto thefts hit $247.4M, second-worst month of 2026 Crypto thefts jumped to $247.4 million in July, more than triple June’s $75 million, making it the second-worst month of 2026 after April’s $644 million, DefiLlama data shows. The biggest hit was the Coldcard exploit, which stole at least $100 million in Bitcoin from 7,300 wallets across three confirmed attack waves, while Galaxy Digital said a suspected fourth wave could push losses to about $130 million.

Security

Researchers Link North Korean Recruitment Malware Campaign to 1,640 Organizations

North Korean hackers hit 1,640 organizations in 57 countries, researchers say Cybersecurity researchers say North Korean operators compromised 1,640 organizations across 57 countries via fake software developer recruitment campaigns, with crypto firms a consistent target. Kumio CTO Vangelis Stykas, who tracked the infrastructure for 22 months, said attackers used malware hidden in coding tests to steal admin access, cloud permissions and wallet credentials, often exploiting contractors with access to multiple companies.

Security

Sui Plans NIST-Approved Post-Quantum Signatures for Accounts and Smart Contract Vaults

Sui to add NIST-approved quantum-resistant signatures Sui said it will integrate two NIST-approved post-quantum signature schemes: ML-DSA-65 for standard accounts and SLH-DSA-SHA2-128s for high-value assets in smart contracts, aiming to reduce the risk that future quantum computers could break today’s on-chain cryptography. Users will be able to migrate with existing recovery phrases, and the feature won’t change consensus or require immediate app updates; vaults are due on mainnet this year, while ML-DSA-65 accounts are targeted for testnet by end-2026 and mainnet in Q1 2027.

August 6, 2026

Security

Chainalysis Says Violent Crypto Thefts Reached $30 Million in First Half of 2026

Chainalysis: violent crypto thefts hit $30M in H1 2026 Violent attacks on crypto holders stole an estimated $30 million in the first half of 2026 alone, putting the year on pace to top 2025’s record $58 million, Chainalysis said. France has driven much of the surge with 30 known incidents by midyear, and investigators linked the spike to a 2024 tax-data leak and a separate Waltio breach affecting about 50,000 users.

Security

Hong Kong police say Fun Coffee crypto scam reports hit 255 and losses reach HK$104 million

Hong Kong losses in alleged Fun Coffee crypto scam reach HK$104 million Hong Kong police said 255 reports have now been filed over the alleged Fun Coffee GCM crypto investment scam, with reported losses rising to about HK$104 million. Investigators say the platform promised 197% to 278% annual returns on USDT deposits before withdrawals stopped and the app went offline on July 20, 2026; six people have been arrested in Hong Kong and two more were detained in Macau as the probe widens.

Security

ZEUS Takes Lightning Infrastructure Offline After Security Incident

ZEUS halts Lightning wallet services after cyber incident ZEUS took its Lightning wallet infrastructure offline on Aug. 5 after a cybersecurity incident, saying the attack was contained and no customer funds were lost or at risk. The outage makes ZEUS the third major Lightning-related service to suspend key operations in about 72 hours after disruptions at Boltz and AQUA, raising concerns around infrastructure providers rather than the Lightning Network itself.

August 5, 2026

August 4, 2026

Security

Boltz Halts Bitcoin Swaps as AI-Assisted Attacks Outpace Security Fixes

Boltz suspends Bitcoin swaps after surge in AI-assisted attacks Boltz has disabled its non-custodial Bitcoin swap service until further notice, saying automated AI-assisted attacks are now finding and exploiting vulnerabilities faster than its team can patch them. The company said no user funds were at risk, cannot give an ETA for a return, and added that its API remains available for cooperative refunds while unilateral refunds still work independently of Boltz infrastructure.

Security

Ledger: Coldcard Exploit Shows Wallet Security Must Keep Up With AI-Era Threats

Ledger says Coldcard exploit highlights hardware RNG and AI risks in wallets Ledger CTO Charles Guillemet said the Coldcard exploit showed how hardware wallet security can fail when seed generation falls back to software randomness: the flaw made some private keys guessable and enabled theft. He said Ledger devices were unaffected because they use a certified hardware RNG in a Secure Element with no software fallback, and argued AI is speeding up vulnerability discovery, making independently certified randomness more critical.

Security

Hong Kong Police Report $9M in Romance Crypto Scams as Malaysia Event Loses Backing

Hong Kong police flag $9M in romance-linked crypto scams in one week Hong Kong police recorded 25 romance scam cases between July 24 and July 30 that cost victims a combined $9 million, including one insurance agent who lost $3.3 million after a fake online boyfriend pushed her into a fraudulent crypto app. The scams typically start on dating or messaging apps, show fake profits, and unravel when victims try to withdraw funds.

Security

Boltz suspends Bitcoin swaps as AI-assisted attacks outpace its security fixes

Boltz halts Bitcoin swap service over AI-assisted hacking attempts Boltz said it is disabling its non-custodial Bitcoin swap service until further notice after a steady rise in automated AI-assisted probing and several contained exploits this year. The team said attackers are now iterating faster than it can find and patch vulnerabilities, and recent security scans showed it could not “responsibly” restart swaps while multiple groups appear to be actively targeting its infrastructure. No user funds were at risk, and the API will stay live for refunds.

August 3, 2026

Security

Boltz Suspends Bitcoin, Lightning and Liquid Swaps After Citing AI-Assisted Attacks

Boltz suspends Bitcoin, Lightning and Liquid swaps after AI-assisted attacks Boltz shut down its non-custodial swap service on Monday until further notice, saying months of automated, AI-assisted probing and several exploits have outpaced the team’s ability to patch its infrastructure. The halt cuts off swap rails used by wallets including Bull Bitcoin and Aqua; Boltz said no user funds were ever at risk and losses were borne by the company, while its API remains online for cooperative refunds on in-flight swaps.