Blink Discloses Admin Tool Breach, Reimburses Users, and Offers 50% Bounty on Stolen Bitcoin
An attacker leveraged stacked permission flaws in inherited support software to drain 6.61 BTC from 24 accounts; Blink contained the breach in fifteen minutes, restored balances from shareholder reserves, and set a 3.3 BTC bounty for fund recovery and circular economies.
In an exhaustive and unusually direct post-mortem published this weekend, custodial wallet provider Blink disclosed a September 19 attack in which an intruder exploited a vulnerability in support administration software to take control of 35 accounts and siphon 6.61 BTC from 24 of them. Within fifteen minutes of a customer alerting engineers at 11:39 UTC, Blink shut down its custodial service entirely. By that evening the security flaw had been patched and the platform reopened. Five days later, all affected customer accounts had been replenished to the satoshi with shareholder capital, ensuring No customer bears any loss.
The post-mortem made no attempt to deflect responsibility onto third-party infrastructure or users. This was our fault. Not Bitcoin's, not our users'.
The vulnerability dated back to October 2023, residing in inherited administrative tools where three permission-checking oversights cascaded together. A user with a basic account could escalate privileges through a web browser, modify account emails or phone numbers, and raise withdrawal thresholds. The team had been heavily engaged in migrating tens of thousands of users toward self-custodial accounts under new regulatory mandates, leaving internal administrative anomalies undetected by monitors geared toward network outages.
While the attacker accessed metadata for 3,817 accounts—primarily phone numbers and email addresses—core cold-storage reserves and non-custodial accounts remained completely untouched. What proved decisive in preventing total drainage was two-factor authentication. Nine accounts targeted by the intruder had 2FA activated; across eighteen attempts to initiate transfers, the attacker was stopped dead with zero loss. By contrast, every one of the 24 drained accounts had two-factor authentication disabled.
Rather than quietly write off the missing funds, Blink announced a 50% recovery bounty—up to 3.3 BTC. Informants providing actionable intelligence that leads to fund recovery will receive 25% of retrieved coins, while another 25% is pledged directly to grassroots circular economies, including Bitcoin Beach in El Salvador, Bitcoin Ekasi in South Africa, and Afribit Kibera in Kenya. As Blink noted, We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief.