NewsCryptoBlink Wallet Restores Services After Attacker Drains Custodial Accounts

Blink Wallet Restores Services After Attacker Drains Custodial Accounts

Author: Crypto Adventure·

Key Takeaways

  • An attacker gained unauthorized access to a few dozen Blink Wallet custodial accounts and withdrew funds, forcing the platform to temporarily shut down.
  • Blink stated that the large majority of customer funds remained secure and that its non-custodial wallets were unaffected by the breach.
  • The company identified every affected account and committed to reimbursing those users without requiring any action on their part.
  • Blink deployed a patch and restored services at approximately 4:19 p.m. ET on September 19, with a full technical post-mortem still pending.
  • The incident occurred as Blink was already winding down custodial services in some regions due to regulatory changes, and followed other recent Bitcoin security events including the Swiss Bitcoin Pay shutdown and SlowMist's warning about the FomoPeek app.
Blink Wallet Restores Services After Attacker Drains Custodial Accounts

Bitcoin payments app Blink Wallet restored its services on September 19 after an attacker gained unauthorized access to a limited number of custodial accounts and withdrew funds, an incident that forced the company to take its platform temporarily offline.

Blink paused operations while it investigated, saying in an update on X that the large majority of customer funds remained secure and that its non-custodial wallets were unaffected. The disruption arrived days after separate security alerts involving DCENT Wallet and Core Lightning, extending a busy September for Bitcoin security teams.

Few Dozen Custodial Accounts Affected

The company later narrowed the scope of the breach to a few dozen custodial accounts. In a follow-up post, Blink said every affected account had been identified and that users would be made whole without needing to take any action.

The company has not disclosed how much Bitcoin or other assets were withdrawn, nor has it published the method the attacker used to gain access to the affected accounts.

Blink's custodial service holds funds on behalf of users, while its non-custodial product gives customers direct control over their own keys. The company launched non-custodial accounts in June using infrastructure designed to let users maintain direct control over their Bitcoin. Blink's security documentation states that its custodial Lightning service keeps the majority of funds in multi-signature cold storage, with a smaller portion held in a hot wallet for payment processing. The company has not said which part of its custodial infrastructure was involved in the September 19 incident.

Patch Deployed and Services Back Online

During the shutdown, Blink said it was deploying a patch while working to bring services back online. The company announced on X that access had been restored at approximately 4:19 p.m. ET, saying the incident had been verified and fixed. Users whose accounts were unaffected could resume using the service following the restoration. Blink said a full post-mortem would follow and is expected to provide additional information about the attack path and remediation.

Earlier Shift Toward Non-Custodial Accounts

The breach came as Blink was already moving parts of its user base toward non-custodial accounts. The company began winding down custodial services in some regions this summer because of regulatory changes, with affected customers given migration or withdrawal options.

The incident also follows the temporary shutdown of Swiss Bitcoin Pay on September 14 after suspected unauthorized access to its internal systems. Separately, blockchain security firm SlowMist recently issued an asset-theft warning involving FomoPeek, an iPhone app marketed for tracking whale wallets that was found to contain malicious code capable of bypassing iOS security restrictions and extracting cryptocurrency wallet credentials from affected devices.

Blink has not yet disclosed the total amount withdrawn or released its technical post-mortem. Its latest incident update confirms services are back online and that affected custodial users will be reimbursed.

Source: Crypto Adventure