Web3 Product Insights

Blink Wallet Hack: Vulnerability Fixed, Company Promises Compensation

Blink Wallet Hack: Vulnerability Fixed, Company Promises Compensation

Bitcoin Lightning wallet Blink Wallet has fixed the vulnerability behind a recent security incident and promised to reimburse affected users.

On September 19, Blink Wallet paused its services while investigating a security incident. The company stated that an attacker had accessed a limited number of custodial accounts and withdrawn funds. The large majority of funds remained secure, and non-custodial wallets were not affected.

Later, Blink confirmed that a few dozen custodial accounts were affected. The company identified all affected accounts and stated that every affected user would be reimbursed.

The vulnerability behind the incident has now been fixed and verified. Blink services were restored for unaffected users, while affected accounts remain temporarily locked as the investigation continues.

This incident became another story among a series of data breaches and wallet hacks that have resulted in users losing funds. On the same day, September 19, MultiversX reported an attempted exploitation of a VM-level vulnerability. According to the team, the attempt caused invalid state changes, so network progression was temporarily paused.

At the same time, in the summer of 2026, Blink added a non-custodial storage option and warned users about a wave of phishing attacks. This highlights another problem: sometimes it is not the system itself that is targeted, but inattentive users.

Blink is considered a notable wallet in the Bitcoin Lightning ecosystem, so the incident attracted attention from the community.

At the moment, there are no details about the exact attack path. Blink has said that a full post-mortem will follow.

Not Your Keys, Not Your Coins

This hack highlights the classic "not your keys, not your coins" problem.

With a custodial model, a vulnerability on the service's side can potentially put the funds of many users at risk. An attacker does not need to compromise individual users if they can exploit the infrastructure that holds their funds.

In this incident, non-custodial wallets were not affected because Blink does not hold the private keys to these funds.

What Can We Learn From This?

The incident highlights one of the main differences between custodial and non-custodial wallets.

With a custodial wallet, users rely on the company to protect and manage the funds held on their behalf. With a non-custodial wallet, the private keys remain under the user's control, but the user also becomes responsible for securing those keys and recovery information.

Non-custodial and hardware wallets are another way of storing funds without relying on a custodial service to hold the private keys. However, they also come with their own risks and responsibilities, such as losing access to your keys or recovery phrase.

Both models carry risks, the only question is who bears them.

This article is for informational purposes only and does not constitute financial, investment, or legal advice. Always conduct your own research before making decisions about storing your assets.

 

How do you rate this article?

2


CrdxRutla
CrdxRutla

I explore the world through business, travel, and global trends. Writing about what I find fascinating along the way.


Web3 Product Insights
Web3 Product Insights

I explore the world of Web3 products, games, and digital economies. Exploring how blockchain is changing our lives and creating new forms of value.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?