The Bitcoin and Lightning payments provider announced the restoration early on September 20, saying the vulnerability responsible for the incident had been fixed and verified. The update followed an approximately seven-hour response period that began on September 19, when Blink initially suspended services while investigating unauthorized withdrawals.
Blink said a “few dozen” custodial accounts were affected, that every impacted account had been identified and that affected users would be made whole. The company has not disclosed how much cryptocurrency was stolen, how the attacker gained access or whether any of the withdrawn funds have been recovered.
A full post-mortem is expected to provide more detail on the attack.
“Services are back online,” Blink said in its restoration update. The company added that unaffected customers could resume normal use of the platform, while the accounts involved in the breach would remain locked temporarily. Blink said those users do not need to take any action while reimbursement and investigation procedures continue.
The distinction between custodial and non-custodial accounts is central to the incident. In Blink’s custodial model, the company manages the infrastructure controlling users’ funds. Its newer non-custodial product instead allows customers to control their own cryptographic keys.
Blink repeatedly stressed that non-custodial balances were never affected by the attack.
That separation has become increasingly important across the digital asset industry as companies experiment with self-custodial blockchain applications designed to reduce users’ exposure to centralized custody providers.
Blink launched its non-custodial accounts in June, using Lightspark’s Spark protocol. Customers receive a 12-word recovery phrase and retain cryptographic control over their Bitcoin rather than depending on Blink to authorize access. Blink has said that even if its own infrastructure disappeared, users could recover funds through compatible Spark software and ultimately exit back to Bitcoin’s base layer.
The company originally developed around the Bitcoin Beach community in El Zonte, El Salvador, where ease of use was prioritized as merchants and consumers began experimenting with everyday Bitcoin and Lightning payments. Blink said it initially chose a custodial model because early Lightning technology made self-custody difficult to offer without sacrificing the simplicity required for mainstream users.
That model has recently begun changing.
In July, Blink announced that it would discontinue custodial accounts for customers in certain regions because of regulatory developments, encouraging those users to migrate to non-custodial accounts. Depending on their individual notifications, affected customers were given August 31 or September 30 deadlines to move balances, although Blink said funds would remain safeguarded for anyone who missed the deadline.
The security incident therefore arrives while Blink is already managing a significant transition in its custody architecture.
It also highlights a broader operational issue for crypto platforms: restoring the service itself does not necessarily restore access for every customer. Similar concerns have appeared when users encounter account holds and withdrawal restrictions elsewhere in the digital asset sector.
For Blink, the immediate technical disruption appears to have been contained. The company says the vulnerability has been corrected, most customer funds were never exposed and normal service has resumed for unaffected users.
What remains unknown is financially important. Without the total amount stolen, investors and industry observers cannot determine the direct cost of reimbursing customers, the size of the exposed custodial pool or whether the attack represents a relatively small account-level incident or a more serious weakness in Blink’s custodial infrastructure.
The most important thing Blink did during this incident was also the simplest: it clearly separated what was compromised from what was not.
Custodial accounts were hit. Non-custodial balances were not.
That distinction matters because crypto security discussions often turn every breach into a claim that the underlying blockchain or payment network failed. Nothing disclosed so far suggests Bitcoin or the Lightning Network itself was compromised. Based on Blink’s statements, the attacker found a vulnerability involving the company’s custodial environment.
But the missing details still matter a lot.
“A few dozen accounts” sounds small. It may ultimately prove to be small. Yet account count tells us very little without knowing the balances involved. Thirty accounts containing a few hundred dollars each is one problem. Thirty high-value accounts is another entirely.
The promise to make customers whole also shifts the immediate financial risk from users to Blink. Unless the stolen assets are recovered or insurance covers the loss, the company will effectively absorb the cost itself.
For now, there is no way to calculate that liability.
The incident also makes Blink’s recent move toward non-custodial architecture look more consequential. Self-custody introduces its own risks — lose the recovery phrase and customer support cannot simply reset the account — but it removes one particularly important attack surface: a centralized operator controlling customer balances.
That does not mean non-custodial users are completely insulated from operational problems. Wallet interfaces, APIs and Lightning infrastructure can still fail. The crypto industry has repeatedly seen how infrastructure outages can temporarily prevent users from interacting with products even when their underlying assets remain safe.
This distinction between asset safety and service availability is worth watching closely.
Blink’s non-custodial users apparently avoided the financial impact of the breach, but the company initially paused broader services while investigating. That is the trade-off modern crypto platforms increasingly have to manage: decentralized ownership can protect funds while parts of the user experience still depend on centralized infrastructure.
Recent platform infrastructure failures elsewhere have demonstrated how quickly operational weaknesses can become reputational issues even when customer assets are not permanently lost.
There is another positive signal here: Blink appears to have moved relatively quickly. It identified the affected accounts, deployed a fix, verified it and restored services within hours rather than leaving the platform offline indefinitely.
But speed of recovery is only one part of incident response.
The post-mortem will matter more.
Users need to know whether the attacker compromised credentials, exploited an application vulnerability, bypassed authorization controls or found a weakness somewhere deeper in Blink’s custody stack. They also need to know how long the vulnerability existed and whether there is evidence it was exploited before September 19.
Those answers determine whether this was a contained incident or evidence of a structural weakness.
Crypto users have become increasingly aware that platforms can exercise substantial control over funds and positions when infrastructure fails or risks emerge, whether through account freezes, withdrawal restrictions or forced platform interventions. Blink’s parallel custodial and non-custodial architecture provides an unusually clean example of how different those risk models can be.
For now, Blink has contained the operational crisis.
The bigger judgment comes later.
If the post-mortem shows a narrow vulnerability that was quickly detected and permanently fixed, the episode may remain a relatively limited security incident. If it reveals deeper weaknesses in authentication, custody or account controls, the fact that only a few dozen users were hit this time becomes much less comforting.
The missing number is still the most important one.
Until Blink says how much was stolen, nobody outside the company can properly measure the financial severity of the breach.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

