Phase two of our 19 September disclosure: a public page that follows the stolen coins, updated as they move.
Follow-up post:

Phase two: following the coins in public
A follow-up to the 19 September post-mortem
Tracking page:
Following the coins of the 19 September 2026 Blink attacker
Bounty terms:

On 3 October we published the post-mortem of the attack and a 50% bounty on the stolen funds. That was about what happened inside Blink. This is about where the money went.
The page lists every address, transaction and Lightning channel we can tie to the attacker. Anyone can check each one on the public blockchain.
Why public:
We want everyone working on the bounty to have the same data we have, as up to date as ours, so they can be as effective as possible. The page is that data: we update it when the coins move and when we confirm something new.
We are unlikely to catch him on our own. He is careful: his main Lightning node is reachable only over Tor, and his activity is spread across all hours of the day. What he cannot hide is the coins. Every time they move, they move in public.
He already knows he is being watched, so publishing tells him nothing new. Formal channels matter and we use them, but they take weeks. A public page reaches exchanges, analysts and other teams the same day.
He is still active:
He prepared for weeks. He set up his Lightning node ten days before the attack, and nine days before it he already controlled about 14 BTC. He has not stopped: in the first week of October his main node opened a new channel, a second node of his showed itself, and he moved coins again.
In the same week, on 5 October, he attacked @secondhq, a company that builds its own version of Ark (a new way to make Bitcoin payments), called Bark. He exploited a bug in Second's Ark server and took 0.75 BTC of their own funds; no user funds were affected (their disclosure:
https://x.com/secondhq/status/2108065406665805992).
He paid for it from the same wallet that received the coins stolen from Blink, and at least partly with those very coins.
We believe he may be preparing a cascading attack: using what he takes from each target to fund the next. If you build on Bitcoin as everyday money, there may be extra reason to be vigilant. If you run a Lightning node, a federation, a swap service or an exchange, check the page against what you see.
What the page shows:
The theft, how the coins moved after it, the coins he held before the attack, his Lightning nodes, his attack on Second's Ark server, and a Lightning wallet that is probably his. Every item is labelled proven, traced or probable. Transactions by exchanges or swap services are marked third-party: they are not accused of anything.
About 0.87 BTC still sits untouched at five of the original addresses, 4.84 BTC at an address that is probably his, and 1.64 BTC at addresses he used in the attack on Second. The whole list downloads as a CSV.
What stays off it:
Anything partners told us in confidence. Personal data. Open security issues. Addresses whose owner we cannot establish. Other teams' incidents, until those teams agree or make them public.
How you can help:
Watch the addresses. If coins move, especially toward an exchange or any service that knows its customers, tell us straight away. Freezes depend on reaching the platform within hours.
Report privately to bounty@blinkbtc.com with BOUNTY in the subject. Please don't post leads publicly: it warns him, and it does not establish your priority.
If you run a service and listed coins reach you, contact us before acting. If you control a listed address and are not involved, write to us and we will correct the page.
The 50% bounty stands. 25% of what is recovered goes to whoever provides the information that leads to it, and another 25% to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. Everything on the page was already known to us, so re-tracing it does not qualify. Where the coins go next can.
Live updates:
Corrections appear as dated notes; we do not silently rewrite it. Spot an error? Write to bounty@blinkbtc.com with CORRECTION in the subject.
We timestamp the page's data on the Bitcoin blockchain with @opentimestamps at launch and with every update.
One more thing:
Blink never charges a fee to recover funds and never asks for keys, seed phrases or payments. Anyone offering "recovery services" in our name is not acting for Blink.