Blink Releases Attack Post-Mortem, Offers Up to 3.3 BTC Bounty
According to Bitcoin News, Blink has released a full post-mortem of the September 19 attack, which resulted in the theft of 6.61 BTC across 24 customer accounts. The…
According to Bitcoin News, Blink has released a full post-mortem of the September 19 attack, which resulted in the theft of 6.61 BTC across 24 customer accounts. The company stated that the vulnerability had existed since October 2023, and any user with a free Blink account could potentially exploit it to gain customer-service-level access, take over customer accounts, and raise withdrawal limits.
The attacker also obtained partial information from 3,817 accounts, including partial phone numbers and email addresses; names, ID documents, addresses, passwords, and seed phrases were not compromised. None of the 24 affected accounts had two-factor authentication enabled. The attacker attempted 18 withdrawals from 9 accounts protected by two-factor authentication, all of which failed.
Blink shareholders have fully reimbursed all affected customers. Approximately 5 BTC of the stolen funds were subsequently moved via cross-chain swap services. Blink is now offering a recovery bounty of up to approximately 3.3 BTC, with half of any recovered funds allocated to those providing actionable leads and the Bitcoin circular economy.
insigtX content is informational and educational, not investment advice.