Bitcoin

Blink Restores Services After Attack on Custodial Lightning Wallet Accounts

Blink restored services after attackers withdrew funds from a few dozen custodial accounts, while its non-custodial Spark wallets remained unaffected.

Blink Restores Services After Attack on Custodial Lightning Wallet Accounts

Blink restored services after deploying a patch following an attack on a limited number of its custodial wallet accounts. The company said its services were back at approximately 4:19 p.m. Eastern Time on September 19, after it had paused operations in response to unauthorized withdrawals.

The incident drew a clear line between Blink's hosted custodial accounts and its newer non-custodial product. Blink said non-custodial wallets were not affected by the breach, according to contemporaneous reporting by The Crypto Times.

Blink restores service after custodial-account withdrawals

Blink paused services on September 19 after an attacker gained access to and withdrew funds from a limited number of custodial accounts. A custodial account is one in which the provider holds the keys used to control funds, making the provider's systems central to account access and transaction processing.

On its status page, Blink reported that it had deployed a patch and restored service at about 4:19 p.m. Eastern Time that day. The update did not specify the technical mechanism used in the attack, the value of funds withdrawn, or the precise number of accounts at the time services returned.

The restoration update matters because the initial response involved a service-wide pause rather than an issue confined to normal account operations for the affected users. Blink did not characterize the event as affecting its non-custodial wallets.

Affected accounts and reimbursement

Blink said a few dozen custodial accounts were affected, that every affected account had been identified, and that users would be made whole without taking action, according to Bitcoin.com News.

The reported impact was confined to a subset of custodial accounts; Blink’s non-custodial wallets were excluded from the reported impact in the company’s statements and subsequent reporting.

Status page marks incident resolved

Blink's status page subsequently marked the custodial-accounts incident as resolved at 08:17 UTC on September 20, following monitoring and remediation updates. That formal resolution came after the September 19 restoration notice, indicating the company continued work on the incident after bringing services back online.

The company said a full post-mortem would follow. Such a report could clarify how the unauthorized access occurred, what the deployed patch addressed and whether Blink introduced additional controls during remediation. None of those details were included in the restoration update on the status page.

The status designation is Blink's operational assessment of the incident after its monitoring period. Its commitment to publish a post-mortem leaves a further disclosure milestone for users seeking a fuller account of the breach and response.

Spark accounts were outside the incident

The attack came less than three months after Blink introduced non-custodial accounts on June 24. In its launch announcement, Blink said the accounts allow users to control their own keys and use the Spark protocol.

That design differs from the custodial arrangement at issue in the September incident. With non-custodial accounts, key control rests with the user rather than with the wallet provider; Blink said those accounts were unaffected.

Blink's next public update is expected to be its promised post-mortem, while the status page records the custodial-account incident as resolved.

Investment Disclaimer

Share this story

X LinkedIn

Related Stories