BLOG |
Blink announcements
A follow-up to the 19 September post-mortem
Today we are publishing a page that follows the stolen coins: Following the coins of the 19 September 2026 Blink attacker. It lists every address, transaction and Lightning channel we can tie to the attacker and publish today, and anyone can check each one on the public blockchain.
On 3 October we published the post-mortem of the 19 September attack: how an attacker took about 6.61 BTC from 24 Blink accounts, how every affected customer was made whole, and a 50% bounty on the stolen funds. Since then, the security advisory for our code has also been published: GHSA-w9wx-p7xr-7jvp. The post-mortem was about what happened inside Blink. This one is about where the money went, and about why we are showing it.
We want everyone working on the bounty to have the same data we have, as up to date as ours, so they can be as effective as possible. The page is that data: we update it when the coins move and when we confirm something new.
We are unlikely to catch him on our own, so we are asking more people to watch. He is careful: his main Lightning node is reachable only over Tor, and his activity is spread across all hours of the day. What he cannot hide is the coins: every time they move, they move in public.
He already knows he is being watched. Publishing tells him nothing new about his own coins. The more people looking, the better the odds that someone sees the coins reach a service that knows its customers.
A link is faster than a request. Formal channels (agreements, law firms, requests for records) matter, and we use them, but they take weeks and cost a lot. Someone who ignores every rule moves faster than that. A public page reaches exchanges, analysts and other teams the same day.
A word on privacy. We build for people's privacy and will keep doing so. This page is different: it follows stolen money moved by the person who stole it, names no one, and holds no personal data. Our community has no settled answer for stolen coins moved with the same privacy tools everyone else uses. Our approach is to publish only what the chain shows about the thief's coins, and to correct ourselves in public. We would like to hear how others would handle it.
He prepared for weeks: he began setting up his Lightning node ten days before the attack on Blink, and nine days before it he already controlled about 14 BTC. He has not stopped since. In early October his main node opened a new channel (1 October), a second node of his showed itself (2 October), two more channels appeared on his main node (3 October), and its first channel was closed and a new one was opened (6 October).
In the same week, on 5 October, he attacked Second, a company that builds its own version of Ark (a new way to make Bitcoin payments), called Bark. He exploited a bug in Second's Ark server, took 0.75 BTC of Second's own funds and kept probing the server until 6 October; no user funds were affected (see Second's disclosure). He funded the attack from the same wallet that received the coins stolen from Blink, and at least partly with those very coins.
Given how active he still is, we believe he may be preparing a cascading attack: using what he takes from each target to fund the next, so that each round leaves him with more to work with. We do not know who is next. As long as he is active, there may be extra reason for teams building on Bitcoin as everyday money to be vigilant.
If you run a Lightning node, a federation, a swap service or an exchange, check the page against what you see. If your project has seen something similar, write to us: we will share what we have first and talk after.
The page tells the story in six chapters, each with a graph you can click through and the full list of addresses and transactions behind it.
Every item carries a label that says how sure we are:
The page also shows where the coins are now. About 0.87 BTC still sits untouched at five of the original addresses. A further 4.84 BTC sits at an address that is probably his, unspent since 28 September. About 1.64 BTC more sits at addresses he used in the attack on Second. Each item shows when it first appeared on chain and the date we first recorded it, and the whole list downloads as a CSV.
"Everything we can" has limits, and we hold to them:
Watch the addresses. If coins from them move, especially toward an exchange or any service that knows its customers, tell us straight away. Freezes depend on reaching the receiving platform within hours.
The 50% bounty stands. Whoever provides the information that leads to a recovery gets 25% of what comes back, and another 25% goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. Everything on the page was already known to us on the date shown, so re-tracing it does not qualify, but new information about where the coins go next can. The terms are at blink.sv/bounty-terms.
The page will change as the coins move. We watch the listed addresses around the clock, and add each movement to the page as soon as possible. New findings go up once we have confirmed them and, where other people are involved, once they agree. Before each update goes live, we re-check every address and transaction against the blockchain.
We will get things wrong sometimes, and we will say so. Corrections appear on the page as dated notes; we do not silently rewrite it. If you spot an error, write to bounty@blinkbtc.com with [CORRECTION] in the subject.
We timestamp the page's data on the Bitcoin blockchain with OpenTimestamps, together with a fingerprint of our full internal list, when the page goes live and with every update. Anyone can then check that everything we list existed by the time it was stamped.
Start receiving and sending bitcoin now