100-Day Trade Challenge: trade on our AI predictions, up to 2 trade ideas a day. Free · educational · unregulated & risky Create free account
Cryptos: 21,667 Exchanges: 1,501 Market Cap: $2.85T 3.72% 24h Vol: $134.78B Dominance: BTC: 58.3% ETH: 11.4% Fear & Greed: 74/100 USD/INR: ₹95.98
Security

Blink Lightning wallet halts services after custodial hack

An attacker drained a few dozen of Blink's custodial accounts, while non-custodial Spark wallets were safe. Blink has patched the flaw and will repay users.

Blink Lightning wallet halts services after custodial hack
Photo: Gifted Individual, public domain, via Flickr

Blink Wallet, an app for Bitcoin payments over the Lightning Network, shut down all of its services on 19 September after finding that an attacker had broken into custodial accounts and moved funds out.

Blink said the breach hit "a limited subset" of accounts, later putting the number at a "few dozen", and stressed that "the majority of funds remain secure."

Which accounts were affected

The dividing line was who controls the keys.

  • Custodial accounts, in which Blink holds the private keys on the user's behalf, were the ones targeted.
  • Non-custodial wallets were not touched. That includes wallets on Spark, the protocol Blink introduced earlier this year.
  • Blink's multisig cold storage, which needs several keys to move funds, helped keep the damage contained.

How Blink responded

The company rolled out an emergency patch and began investigating exactly how the attacker got in. By Saturday evening it said services were running again. Blink has committed to compensating every affected user, but it has not yet disclosed how much was stolen or what the technical root cause was.

The wider picture

The timing is awkward. Blink is already moving away from custodial services in some regions because of regulatory pressure, with migration deadlines falling between August and September 2026.

It has also been a difficult spell for Lightning software in general. BTCPay Server recently disclosed a critical bug that exposed LND macaroons (the credentials that control access to a Lightning node) and led to real losses. LDK, a Lightning development kit, has patched two vulnerabilities of its own.

What Indian users should take from it

Whenever someone else holds the keys to your coins, you carry counterparty risk. That is true of an exchange, and it is equally true of the custodial mode inside a wallet app. A sensible split is to keep trading funds on the platform you actually trade on, hold long-term savings in a wallet where you control the keys, and treat convenient custodial wallets as pocket money rather than a savings account.


This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.

Put it into practice

Run the 100-trade challenge: cap every loss, log every trade, and find out honestly whether you have an edge.