Key Takeaways
Blink restored services after a security breach affected a few dozen custodial accounts.
The company says non-custodial wallets were unaffected and all affected users will be reimbursed.
Blink has not disclosed the stolen amount or attack method and plans to publish a full post-mortem.
Blink’s Security Incident
Blink Wallet has restored its services after an attacker gained access to a limited number of custodial accounts and withdrew funds.
The Bitcoin and Lightning Network wallet provider paused its services on September 19, 2026, while it investigated the security incident. Blink later said that a “few dozen” custodial accounts were affected.
The company has not said how much money was stolen. However, it said the large majority of funds remained safe and promised to fully reimburse every affected user.
“We’ve paused Blink services while we investigate a security incident,” Blink said in a post on X. The company said an attacker had “accessed a limited number of custodial accounts and withdrew funds.”
The incident involved Blink’s custodial wallets. With a custodial wallet, the service provider controls the keys needed to move the funds. Blink said its non-custodial wallets were not affected. In those wallets, users control their own keys and funds.
In a later update, Blink confirmed that a “few dozen custodial accounts were affected by the incident.” It also said that every affected account had been identified.
“Every affected account is identified and will be made whole,” Blink said. The company has not released the total amount taken by the attacker. Because of that, the financial impact of the incident is still unclear.
Blink paused its services while its team investigated the breach and worked on a security fix.
The shutdown meant users temporarily could not access the platform. Some users turned to Blink's social media account for information about when services would return.
One user said they urgently needed access to their funds for funeral payments and asked how long the service would remain unavailable.
Blink replied, “We are working on restoring service as soon as possible. A patch is being deployed. We will update shortly.”
Blink later announced that its services were back online. The company said the vulnerability had been fixed and verified. It also said users who were not affected could continue using the service.
“Non-custodial balances were never affected,” Blink said in its update.

Blink Wallet on X
Affected custodial accounts were expected to remain temporarily locked while Blink completed its response to the incident.
One of the biggest unanswered questions is how the attacker gained access to the affected accounts. Blink has confirmed that funds were withdrawn, but it has not publicly explained the attack method. The company has also not released a detailed post-mortem.
That means there is currently no confirmed information showing whether the attacker used stolen credentials, a software vulnerability, or another method.
Blink said a full post-mortem would be released later. Until then, claims about the specific attack method should be treated as unconfirmed.
The Blink incident comes during a period of several security problems affecting digital assets and Lightning Network projects.
BTCPay Server recently disclosed a critical bug that could allow an attacker to access LND macaroon files. The Lightning Development Kit also disclosed vulnerabilities and advised users to upgrade.
The non-custodial swap service Boltz experienced security problems in August 2026. Its team warned that attackers were moving faster than its ability to find and fix vulnerabilities.
These incidents show the security challenges facing Bitcoin, Lightning and the wider digital asset industry. Even when an incident is limited to a small number of accounts, users can face temporary loss of access to their funds while a platform investigates and fixes the problem.





