September 20, 2026

Blink Wallet halted: custodial accounts breached. Non-custodial ones — untouched. That's the whole lesson

On September 19 the Lightning wallet Blink (formerly Bitcoin Beach Wallet, El Salvador) posted on X: "An attacker accessed a limited number of custodial accounts and withdrew funds. The large majority of funds are secure, and non-custodial wallets are unaffected." Platform services are suspended pending investigation. Amount, number of accounts, access vector and a resumption date — none disclosed.

The irony is in the dates. Back on July 1 Blink announced it was discontinuing custodial accounts "in regions where regulatory developments affect custodial services": migrate to non-custodial or withdraw, deadlines August 31 / September 30. The accounts that got breached were already living out their last days.

What a custodial Lightning balance actually is: not your UTXOs, but a row in the service's database. The keys are the service's. Three consequences follow, and you only see them on incident day:

A non-custodial wallet knows none of this — unless you typed your seed phrase into someone's app (hello, D'CENT, which we covered yesterday).

If you use Blink:

Everyone else — 5 minutes: go through your wallets and ask about each one, "do I hold a seed phrase?" No — it's custodial, and it should hold only working balances. Custodial isn't "bad" — it's a line of credit you extend to the service. Just know its size.

And the practical part. Bitcoin stolen from Blink will move through fresh addresses to exchanges — and exchanges will freeze linked deposits. Received BTC from an unknown address this week? Screen the sender before you send it to an exchange.

Check an address → https://t.me/amlconsensus_bot?start=en (first check is free)

Sources: Blink on X, Sep 19, 2026; Blink blog Jul 1 and Jul 31, 2026; SlowMist.

Screen your counterparty now

Consensus of sources · verdict across 35 chains · connection graph and full audit · PDF with QR verification

Open @amlconsensus_bot — 1 free check