Blink Wallet pauses services after attacker drains custodial accounts

1 hour ago 18

Blink Wallet, a Bitcoin Lightning Network payments app, shut down all services on September 19 after discovering that an attacker had accessed and drained funds from a limited number of its custodial accounts. The company confirmed it has deployed a patch to address the vulnerability, though the full scope of the damage remains unclear.

The breach hit custodial accounts specifically, meaning wallets where Blink holds the keys on behalf of users. Non-custodial wallets, where users manage their own private keys, were not affected.

What we know so far

Blink Wallet shared the news via a post on X, confirming unauthorized access to what it described as a limited subset of custodial accounts. The attacker managed to withdraw funds, though the company has not disclosed how much was taken or how many accounts were compromised.

The company moved quickly to reassure users that the majority of funds remain secure. Blink’s custodial infrastructure uses a multisig cold storage system paired with smaller hot wallet components, a setup designed to limit exposure in exactly this kind of scenario.

An investigation is underway to determine the precise breach vector. Blink stated it has already deployed a patch, suggesting the team identified at least the surface-level exploit.

One thing the company was explicit about: the Spark protocol, which powers Blink’s non-custodial wallet offering introduced in mid-2026, was not implicated in the breach.

Timing adds an uncomfortable layer

The breach arrives at a particularly awkward moment for Blink. The company has been in the process of winding down custodial services in select regions due to regulatory changes, with user migration deadlines set for August and September 2026. Some users were presumably still in the middle of transitioning their funds when the attacker struck.

Blink’s decision to introduce non-custodial wallets via Spark earlier in 2026 now looks prescient. The company was already nudging users toward self-custody, partly driven by regulatory pressure. The breach just accelerated the argument for that shift in the most painful way possible.

Custodial risk in the Lightning era

Bitcoin’s Lightning Network was built to make payments fast and cheap. But running your own Lightning node isn’t trivial, which is why custodial wallets like Blink gained popularity in the first place. When a custodial service pools user funds and manages keys on their behalf, it creates a honeypot. One successful breach can drain many accounts at once, rather than requiring an attacker to compromise individual wallets one by one.

Blink’s multisig cold storage setup should have limited the blast radius, and by the company’s own account, it did. Most funds were reportedly unaffected.

What this means for custodial services

Regulatory bodies in multiple jurisdictions have been tightening requirements for custodial crypto services. Blink was already responding to that pressure by winding down custodial operations in certain regions. The Spark protocol that Blink introduced for self-custody was designed to give users direct control of their keys while still leveraging Lightning’s speed advantages.

For now, Blink’s services remain paused. Users with custodial accounts are waiting for the investigation to conclude and for the company to clarify who lost what and how, or whether, they’ll be made whole.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article