Blink Wallet's avatar
Blink Wallet
community@blink.sv
npub13ljn...cfhw
making bitcoin everyday money
Blink Wallet's avatar
Blink Wallet 9 hours ago
The Weekly Brief is back after a three-week pause, with four weeks in one edition. South Africa's FNB opened Bitcoin buying to nearly 9 million clients, but the coins are ringfenced: no transfers in or out, so no paying a merchant and no moving them to your own wallet. Access to Bitcoin as an investment, not as money. The comment period on the country's draft crypto rules closed September 30; the Reserve Bank says they're not final. On the ground: shops in Kimbo, Kenya ran a week of 10–15% Bitcoin discounts, someone paid for fuel in sats at a Cape Town petrol station, and a phone shop in a Dominican mountain village got its first walk-in Bitcoin customer, with no campaign behind it. The rails had a rough month: Liquid peg-outs stayed frozen, Swiss Bitcoin Pay went offline for six days, and Core Lightning shipped two security releases in two weeks. If you run CLN, update to 26.06.9.
Phase two of our 19 September disclosure: a public page that follows the stolen coins, updated as they move. Follow-up post: Tracking page: Bounty terms: On 3 October we published the post-mortem of the attack and a 50% bounty on the stolen funds. That was about what happened inside Blink. This is about where the money went. The page lists every address, transaction and Lightning channel we can tie to the attacker. Anyone can check each one on the public blockchain. Why public: We want everyone working on the bounty to have the same data we have, as up to date as ours, so they can be as effective as possible. The page is that data: we update it when the coins move and when we confirm something new. We are unlikely to catch him on our own. He is careful: his main Lightning node is reachable only over Tor, and his activity is spread across all hours of the day. What he cannot hide is the coins. Every time they move, they move in public. He already knows he is being watched, so publishing tells him nothing new. Formal channels matter and we use them, but they take weeks. A public page reaches exchanges, analysts and other teams the same day. He is still active: He prepared for weeks. He set up his Lightning node ten days before the attack, and nine days before it he already controlled about 14 BTC. He has not stopped: in the first week of October his main node opened a new channel, a second node of his showed itself, and he moved coins again. In the same week, on 5 October, he attacked @secondhq, a company that builds its own version of Ark (a new way to make Bitcoin payments), called Bark. He exploited a bug in Second's Ark server and took 0.75 BTC of their own funds; no user funds were affected (their disclosure: https://x.com/secondhq/status/2108065406665805992). He paid for it from the same wallet that received the coins stolen from Blink, and at least partly with those very coins. We believe he may be preparing a cascading attack: using what he takes from each target to fund the next. If you build on Bitcoin as everyday money, there may be extra reason to be vigilant. If you run a Lightning node, a federation, a swap service or an exchange, check the page against what you see. What the page shows: The theft, how the coins moved after it, the coins he held before the attack, his Lightning nodes, his attack on Second's Ark server, and a Lightning wallet that is probably his. Every item is labelled proven, traced or probable. Transactions by exchanges or swap services are marked third-party: they are not accused of anything. About 0.87 BTC still sits untouched at five of the original addresses, 4.84 BTC at an address that is probably his, and 1.64 BTC at addresses he used in the attack on Second. The whole list downloads as a CSV. What stays off it: Anything partners told us in confidence. Personal data. Open security issues. Addresses whose owner we cannot establish. Other teams' incidents, until those teams agree or make them public. How you can help: Watch the addresses. If coins move, especially toward an exchange or any service that knows its customers, tell us straight away. Freezes depend on reaching the platform within hours. Report privately to bounty@blinkbtc.com with BOUNTY in the subject. Please don't post leads publicly: it warns him, and it does not establish your priority. If you run a service and listed coins reach you, contact us before acting. If you control a listed address and are not involved, write to us and we will correct the page. The 50% bounty stands. 25% of what is recovered goes to whoever provides the information that leads to it, and another 25% to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. Everything on the page was already known to us, so re-tracing it does not qualify. Where the coins go next can. Live updates: Corrections appear as dated notes; we do not silently rewrite it. Spot an error? Write to bounty@blinkbtc.com with CORRECTION in the subject. We timestamp the page's data on the Bitcoin blockchain with @opentimestamps at launch and with every update. One more thing: Blink never charges a fee to recover funds and never asks for keys, seed phrases or payments. Anyone offering "recovery services" in our name is not acting for Blink.
Blink Wallet's avatar
Blink Wallet 6 days ago
Informe completo sobre el ataque del 19 de septiembre y una recompensa del 50% —hasta 3.3 BTC— sobre los fondos robados: Términos de la recompensa: El sábado 19 de septiembre un atacante usó una falla en nuestras herramientas administrativas para tomar el control de 35 cuentas de Blink y retirar unos 6.61 BTC de 24 de ellas. A las 11:39 UTC un cliente llamó a uno de nuestros ingenieros. Quince minutos después todo el servicio custodial estaba apagado. Esa misma noche la falla estaba cerrada y el servicio había vuelto. El jueves 24 de septiembre, cada cliente afectado tenía de vuelta su saldo exacto, en bitcoin y en dólares, pagado por los accionistas de Blink. Ningún cliente asume pérdida alguna. La culpa fue nuestra. No de Bitcoin, no de nuestros usuarios. A los 22 clientes a quienes les robaron bitcoin, y a las 3,817 personas cuyos datos de cuenta fueron consultados: lo sentimos. Cómo pasó: Desde octubre de 2023 hasta ese sábado, cualquier persona con una cuenta gratuita de Blink y un navegador podía darse a sí misma los poderes de nuestro equipo de soporte: cambiar el correo o el teléfono de cualquier cuenta, iniciar sesión como ese cliente y subir sus límites. Tres errores comunes en cómo nuestras herramientas administrativas revisaban permisos, uno encima del otro, en código que heredamos. Todo el equipo estaba ocupado migrando a decenas de miles de usuarios a la autocustodia bajo una nueva regulación. Un monitoreo pensado para detectar caídas del servicio no detectó a un administrador haciendo lo que ningún administrador debería hacer. Lo que no tocó: El dinero salió de nuestra billetera operativa. La mayoría de los fondos de los clientes está en almacenamiento en frío con firma múltiple, que nada en nuestras herramientas administrativas puede alcanzar. Las cuentas no custodiales nunca estuvieron en juego: no tenemos esas llaves. Lo que vio el atacante: También consultó datos de otras 3,817 cuentas; en algunos casos, un número de teléfono o un correo electrónico. No vio nombres, documentos de identidad, direcciones, contraseñas ni frases semilla. Escribimos a cada titular que pudimos contactar con el detalle exacto de lo que se vio. Lo que lo frenó: La autenticación de dos factores. El atacante inició sesión en nueve cuentas que la tenían activada e intentó dieciocho veces mover dinero. Cero pérdidas. Ninguna de las 24 cuentas vaciadas la tenía activada. Si haces una sola cosa después de leer esto: Configuración → Seguridad y privacidad → Autenticación de dos factores. Y actívala también en tu correo electrónico. Lo que cambiamos: La falla se cerró el mismo día y dos días después se agregó una tercera capa de protección. Las herramientas administrativas ya no están expuestas a internet. Las funciones que cambian el correo o el teléfono de un cliente están desactivadas para todos mientras las rediseñamos. Se revocaron todas las claves de API de los clientes. La billetera operativa guarda ahora una fracción de lo que guardaba. Las correcciones de seguridad se desarrollan en privado y se publican una vez desplegadas; el código sigue siendo abierto. Ya funciona un canal permanente para reportar problemas de seguridad, con recompensas de hasta 0.1 BTC por hallazgos críticos. Dónde está el dinero: Una parte sigue donde se retiró. Unos 5 BTC pasaron por un servicio de intercambio entre cadenas; una cantidad pequeña llegó a un exchange que está colaborando. Hay denuncias penales presentadas en El Salvador y en Próspera, los reguladores están notificados y hemos rastreado los fondos sin interrupción. No esperamos recuperar el dinero. Por eso ofrecemos una recompensa del 50%. Quien aporte la información que lleve a una recuperación recibe el 25% de lo que se recupere. Otro 25% de todo lo que se recupere va a Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera y las economías circulares que ellos elijan. Sin tope, sin fecha de vencimiento, y se paga solo con fondos que efectivamente vuelvan. Escribe a bounty@blinkbtc.com. Habríamos preferido mil veces destinar este dinero a la adopción de Bitcoin desde las bases que perderlo a manos de un ladrón. Debería darle vergüenza al atacante. Una cosa más: Ignora cualquier correo o SMS sobre este incidente que traiga un enlace: a los usuarios afectados les escribimos solo con mensajes dentro de la app de Blink. Nunca te pediremos tu PIN, tu contraseña, tu frase semilla ni un código de acceso. El informe completo tiene la cronología, el detalle técnico para quien opere código derivado del nuestro y los términos de la recompensa (enlaces al principio). Blink nació como la billetera de todos los días de un pequeño pueblo de playa donde la gente necesitaba dinero que funcionara. El 19 de septiembre, para 22 de nuestros clientes, no funcionó. Cada uno de ellos nos había confiado su dinero, que es lo único para lo que existe un custodio. A nuestros clientes, a los investigadores y exchanges que ayudaron en cuestión de horas, a los accionistas que respaldaron a la empresa sin dudarlo y al equipo que dejó todo un sábado: gracias. Recuperaremos la confianza como se ganó en El Zonte: estando presentes y logrando que los pagos pasen, todos los días.
Blink Wallet's avatar
Blink Wallet 6 days ago
Full post-mortem of the September 19 attack, and a 50% bounty — up to 3.3 BTC — on the stolen funds: Bounty terms: On Saturday September 19 an attacker used a flaw in our admin tools to take over 35 Blink accounts and withdraw about 6.61 BTC from 24 of them. A customer called one of our engineers at 11:39 UTC. Fifteen minutes later the whole custodial service was off. By that evening the hole was closed and the service was back. By Thursday September 24 every affected customer had their exact balance back, in bitcoin and in dollars, paid for by Blink's shareholders. No customer bears any loss. This was our fault. Not Bitcoin's, not our users'. To the 22 customers whose bitcoin was taken, and to the 3,817 people whose account details were looked up: we are sorry. How it happened: From October 2023 until that Saturday, anyone with a free Blink account and a web browser could give themselves the powers of our support staff: change the email or phone on any account, log in as that customer, raise their limits. Three unremarkable mistakes in how our admin tools checked permissions, stacked on top of each other, in code we inherited. The whole team was busy moving tens of thousands of users to self-custody under new regulation. Monitoring built to catch outages didn't catch an administrator doing things no administrator should. What it didn't touch: The money came out of our hot wallet. Most customer funds sit in multi-signature cold storage that nothing in our admin tools can reach. Non-custodial accounts were never in play: we don't hold those keys. What the attacker saw: They also read the details of 3,817 other accounts, in some cases a phone number or email address. Not names, not IDs, not addresses, not passwords, not seed phrases. We wrote to every holder we could reach, saying exactly what was seen. What stopped them: Two-factor authentication. The attacker logged in to nine accounts that had it on and tried eighteen times to move money. Zero loss. None of the 24 drained accounts had it on. If you take one thing from this post: Settings → Security and Privacy → Two-factor authentication. Then turn it on for your email too. What we changed: The flaw was fixed the same day and a third layer added two days later. The admin tools are off the public internet. The functions that change a customer's email or phone are switched off for everyone while we redesign them. All customer API keys were revoked. The hot wallet now holds a fraction of what it did. Security fixes are developed privately and published once deployed; the code stays open source. A standing security reporting channel is live, with rewards of up to 0.1 BTC for critical findings. Where the money is: Some still sits where it was withdrawn to. About 5 BTC has gone through a cross-chain swap service; a small amount reached an exchange that is cooperating. Criminal complaints are filed in El Salvador and Próspera, the regulators are notified, and we have traced the funds continuously. We are not expecting the money back. So we are putting a 50% bounty on it. Whoever provides the information that leads to a recovery gets 25% of what is recovered. Another 25% of anything recovered goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. No cap, no end date, paid only out of funds that actually come back. Write to bounty@blinkbtc.com. We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief. Shame on the attacker. One more thing: Ignore any email or SMS about this incident that contains a link: we contacted affected users only through messages in the Blink app. We will never ask for your PIN, password, seed phrase or a login code. The full post-mortem has the timeline, the technical detail for anyone running code derived from ours, and the bounty terms (links at the top).
Blink Wallet's avatar
Blink Wallet 2 months ago
Accepting Bitcoin just got easier: the new BTCPay plugin turns a Blink Lightning address into a full merchant setup — no node, no API key, your keys. Lightning Labs ships Wavelength, pooled sats buy a cow, and a town in El Salvador pays for laundry, juice, and coffee in bitcoin — this week's brief.
Blink Wallet's avatar
Blink Wallet 2 months ago
Accept Bitcoin on BTCPayserver with Blink — now with non-custodial accounts. Connect with just your Blink lightning address, keep custody of your funds, and skip the technical hassle. See it work in under 5 minutes Get started → blink.sv/btcpay Plugin → Docs →
Blink Wallet's avatar
Blink Wallet 5 months ago
Blink Wallet's avatar
Blink Wallet 11 months ago
When you can pay for everything with bitcoin - what changes next?
Blink Wallet's avatar
Blink Wallet 1 year ago
New post! ​Inflation is a hidden tax on everyone. Our new guide breaks down the "Cantillon Effect" and why Bitcoin is the peaceful revolution against the money printer. ​Read more: blink.sv/blog/inflation
Blink Wallet's avatar
Blink Wallet 1 year ago
"I use Blink for onboarding newbies, but it's a turn-off when SMS doesn't arrive instantly... 😪" Say no more, fam 🧑‍🔧 With the latest version of Blink, it's possible to add phone number later, so onboarding is Lightning⚡️ fast!
Blink Wallet's avatar
Blink Wallet 1 year ago
Lightning? ⚡️ Bitcoiners asked for it. We built it. Everybody uses it. The consequence? Fast, low-cost transactions. 🎉 But no sleeping. Let's keep on building 🚀 image
↑