READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Blink Wallet Pauses Services After Hacker Drains Dozens of Custodial Accounts

Blink Wallet Pauses Services After Hacker Drains Dozens of Custodial Accounts
Blink Wallet, a Bitcoin Lightning Network payments app, shut down operations on Saturday, September 19, after an attacker broke into a limited number of custodial accounts and withdrew funds. The company says a patch is deployed, non-custodial users are untouched, and every affected account will be made whole, but it still hasn't said how much was stolen or how the attacker got in.

Blink Wallet halted all services on Saturday, September 19, after discovering that an attacker had broken into a subset of its custodial accounts and pulled funds out. The company confirmed the breach in a post on X: "We've paused Blink services while we investigate a security incident. An attacker accessed a limited number of custodial accounts and withdrew funds."

In a follow-up post, Blink narrowed the scope, saying a "few dozen" custodial accounts were affected. The company has not disclosed a dollar figure for the theft, how many total accounts exist on the platform, or the specific method the attacker used to get in.

What Blink has said clearly: the large majority of custodial funds are secure, and non-custodial wallets, where users hold their own private keys, were not touched at all. The company's custodial setup runs a multisig cold storage system paired with smaller hot wallet components, a structure meant to cap losses if something like this happens. It appears to have worked as designed for most accounts, even if it didn't stop every one.

Blink also made a specific promise: "every affected account is identified and will be made whole," according to the company's statement carried by Bitcoin.com News. No timeline was attached to that pledge, and as of Blink's last public update at 12:06 p.m. ET Saturday, no post-mortem or breakdown of the attack vector had been published.

One user replying to Blink's thread on X said they needed access to funds immediately for funeral payments. Blink's account responded only that a patch was being deployed and service would be restored "as soon as possible." Until Blink publishes an actual post-mortem, anyone claiming to know the exact exploit is guessing.

A wrinkle on Spark

Crypto Briefing reported that Blink was explicit the breach did not involve Spark, the non-custodial protocol Blink introduced in mid-2026 that also powers other Lightning wallets. But ChainCatcher's reporting, drawing on the same Bitcoin.com News reporting, framed it more cautiously: Spark "has not yet been confirmed" as unconnected to the incident. That's a meaningful difference. One framing treats Spark as cleared; the other treats it as merely unconfirmed either way. Readers should treat Spark's status as unresolved until Blink issues a formal post-mortem naming the breach vector.

Bad timing for a company already pushing self-custody

The breach lands at an awkward moment. Blink has been winding down custodial services in certain regions because of regulatory changes, with user migration deadlines set for August and September 2026, according to Crypto Briefing. Some users may have still been mid-transition when the attacker struck.

The self-custody argument is straightforward: when a platform holds the keys for thousands of users, one successful breach can drain many accounts at once instead of forcing an attacker to compromise each person individually. That's the honeypot problem baked into any custodial model, and it's a real argument in favor of individuals controlling their own keys.

But that argument has a real-world limit. Running a personal Lightning node is not trivial for most people, which is exactly why custodial wallets like Blink became popular in the first place. Telling ordinary users to self-custody doesn't help someone who needs to pay for a funeral this weekend and instead finds their app locked down with no clear timeline. Convenience and security are in genuine tension here, and Blink's own migration push shows the company knows it.

Part of a rough stretch for Lightning Network apps

Blink's outage is not an isolated event. Crypto Times reported that Nostra Finance, a Starknet-based lending protocol, paused its money market on September 17 after a manipulated price feed let one account borrow roughly $3.5 million against inflated collateral. Separately, Blockaid's exploit detection system flagged an attack on older Flamincome contracts tied to FlamingoFinance on September 16, where an attacker used an $18 million flash loan to net an estimated $345,900 profit.

Bitcoin.com News also noted a string of recent Lightning-specific problems: a BtcPay Server bug that could let a remote attacker read LND macaroon files, two disclosed bugs in the Lightning Development Kit, and an August 3 shutdown at the non-custodial swap service Boltz, whose team said "attackers now iterate faster than a team our size can find and patch."

Crypto Times separately tallied roughly $322 million in reported crypto exploits between September 1 and September 7, 2026, with more than 99% of that tied to a single incident on the Bitcoin sidechain Liquid Network. ChainCatcher reported that Liquid attackers had returned 3,400 BTC by September 8, with about 600 BTC still outstanding.

Blink users are now waiting on two things: a working app, and an actual explanation of how a company using multisig cold storage still lost funds from dozens of accounts. Until Blink publishes that post-mortem, the precise loss total and the exact vulnerability remain unknown.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingBlink Wallet pauses services after attacker drains custodial accounts
right
Epoch TimesThe 24-Hour Action Plan for a Stolen Wallet
unknown
Crypto TimesBlink Wallet Pauses Services After Attack on Custodial Accounts
unknown
unknownBlink Pauses Services to Investigate Security Incident; Attackers Access Custodial Accounts
unknown
Chain CatcherBlink suspends services and investigates security incidents
unknown
Ground NewsBlink Wallet Hit by Attacker, ‘Few Dozen’ Custodial Accounts Drained
unknown
Bitcoin.com NewsBlink Wallet Hit by Attacker, 'Few Dozen' Custodial Accounts Drained