BLOG |

Blink announcements

Phase two: following the coins in public

A follow-up to the 19 September post-mortem

Phase two: following the coins in public
October 8, 2026
Blink team

Today we are publishing a page that follows the stolen coins: Following the coins of the 19 September 2026 Blink attacker. It lists every address, transaction and Lightning channel we can tie to the attacker and publish today, and anyone can check each one on the public blockchain.

On 3 October we published the post-mortem of the 19 September attack: how an attacker took about 6.61 BTC from 24 Blink accounts, how every affected customer was made whole, and a 50% bounty on the stolen funds. Since then, the security advisory for our code has also been published: GHSA-w9wx-p7xr-7jvp. The post-mortem was about what happened inside Blink. This one is about where the money went, and about why we are showing it.

‍

Why we are showing everything we can

We want everyone working on the bounty to have the same data we have, as up to date as ours, so they can be as effective as possible. The page is that data: we update it when the coins move and when we confirm something new.

We are unlikely to catch him on our own, so we are asking more people to watch. He is careful: his main Lightning node is reachable only over Tor, and his activity is spread across all hours of the day. What he cannot hide is the coins: every time they move, they move in public.

He already knows he is being watched. Publishing tells him nothing new about his own coins. The more people looking, the better the odds that someone sees the coins reach a service that knows its customers.

A link is faster than a request. Formal channels (agreements, law firms, requests for records) matter, and we use them, but they take weeks and cost a lot. Someone who ignores every rule moves faster than that. A public page reaches exchanges, analysts and other teams the same day.

A word on privacy. We build for people's privacy and will keep doing so. This page is different: it follows stolen money moved by the person who stole it, names no one, and holds no personal data. Our community has no settled answer for stolen coins moved with the same privacy tools everyone else uses. Our approach is to publish only what the chain shows about the thief's coins, and to correct ourselves in public. We would like to hear how others would handle it.

‍

He is still active and may be preparing a cascading attack

He prepared for weeks: he began setting up his Lightning node ten days before the attack on Blink, and nine days before it he already controlled about 14 BTC. He has not stopped since. In early October his main node opened a new channel (1 October), a second node of his showed itself (2 October), two more channels appeared on his main node (3 October), and its first channel was closed and a new one was opened (6 October).

In the same week, on 5 October, he attacked Second, a company that builds its own version of Ark (a new way to make Bitcoin payments), called Bark. He exploited a bug in Second's Ark server, took 0.75 BTC of Second's own funds and kept probing the server until 6 October; no user funds were affected (see Second's disclosure). He funded the attack from the same wallet that received the coins stolen from Blink, and at least partly with those very coins.

Given how active he still is, we believe he may be preparing a cascading attack: using what he takes from each target to fund the next, so that each round leaves him with more to work with. We do not know who is next. As long as he is active, there may be extra reason for teams building on Bitcoin as everyday money to be vigilant.

If you run a Lightning node, a federation, a swap service or an exchange, check the page against what you see. If your project has seen something similar, write to us: we will share what we have first and talk after.

‍

What the page shows

The page tells the story in six chapters, each with a graph you can click through and the full list of addresses and transactions behind it.

  1. The theft, 19 September. The eight addresses he typed in as withdrawal destinations, Blink's 12 payout transactions, and two Lightning swap-outs that brought part of the Lightning money back on chain within an hour.
  2. Following the coins. How he combined the stolen coins with coins of his own on 20 September, paid chunks into a cross-chain swap service over the following days, and on 28 September spent stolen coins together with coins he already held before the attack (chapter 3).
  3. Before the attack, 10–11 September. The roughly 14 BTC he held as ecash in Fedimint federations: 435 redemptions (peg-outs) to one address of his, and the coins he later spent together with the stolen ones. The federations are not involved: they are community federations used by many people, and coins still inside them belong to other users.
  4. His Lightning nodes. Blink's payment records show at least 146,639,697 sats of the Lightning withdrawals going to his node, aegis-ln. Most of its capacity was inbound liquidity opened by LNBiG, a large node operator; that money is LNBiG's, not his. A second node, green, showed itself to be his on 2 October.
  5. Second's Ark server, 5–6 October. How he paid round amounts, some of them stolen coins, into Second's Ark server and took them straight back out to two addresses of his, and how on 6 October he moved 50,000,000 sats from one of those into a new channel on aegis-ln.
  6. His Lightning wallet. A Lightning wallet whose channel history goes back to January 2024. On 5 October, 35,000,000 sats came out of it into his wallet, and part went into the attack on Second; that afternoon the channel was closed. We mark the wallet itself probable: the link to him runs through that one transaction.

Every item carries a label that says how sure we are:

Label What it means
provenThe blockchain shows it directly: an address he typed in, or coins spent together with his (only the holder of both keys can do that)
tracedFollowed through his own transactions, such as the change of a payment he made; strong, but it relies on reading which output is his
probableOur best reading of a pattern; not proven, so treat it with care
third-partyA transaction by someone else, such as an exchange or swap service; they are not accused of anything

‍

The page also shows where the coins are now. About 0.87 BTC still sits untouched at five of the original addresses. A further 4.84 BTC sits at an address that is probably his, unspent since 28 September. About 1.64 BTC more sits at addresses he used in the attack on Second. Each item shows when it first appeared on chain and the date we first recorded it, and the whole list downloads as a CSV.

‍

What stays off the page

"Everything we can" has limits, and we hold to them:

  • What others told us in confidence. Companies and projects that shared information with us did so under agreements or on trust. We keep it that way.
  • Personal data. No names, email addresses, phone numbers or IP addresses, and nothing about our customers.
  • Open security issues. Ours or anyone else's, until they are fixed.
  • Addresses whose owner we cannot establish. He paid people and services; a coin he sent is not his once it arrives. Services that received coins are shown as counterparties, never as his.
  • Other teams' incidents. Where the trail leads to another project, we describe it only once that team agrees or has made it public itself.

‍

How you can help

Watch the addresses. If coins from them move, especially toward an exchange or any service that knows its customers, tell us straight away. Freezes depend on reaching the receiving platform within hours.

  • Report privately to bounty@blinkbtc.com with [BOUNTY] in the subject. You can encrypt with our PGP key.
  • Don't post leads publicly. It warns him, and it does not establish your priority: submissions rank by the time they reach us.
  • Tell us what the page doesn't show, such as who controls an address, a node or an account linked to these coins.
  • If you run a service and listed coins reach you, contact us before acting. The page is information, not a request to freeze anything.
  • If you control a listed address and are not involved, for example because you received coins in good faith, write to us and we will correct the page.

The 50% bounty stands. Whoever provides the information that leads to a recovery gets 25% of what comes back, and another 25% goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. Everything on the page was already known to us on the date shown, so re-tracing it does not qualify, but new information about where the coins go next can. The terms are at blink.sv/bounty-terms.

‍

Live updates and corrections

The page will change as the coins move. We watch the listed addresses around the clock, and add each movement to the page as soon as possible. New findings go up once we have confirmed them and, where other people are involved, once they agree. Before each update goes live, we re-check every address and transaction against the blockchain.

We will get things wrong sometimes, and we will say so. Corrections appear on the page as dated notes; we do not silently rewrite it. If you spot an error, write to bounty@blinkbtc.com with [CORRECTION] in the subject.

We timestamp the page's data on the Bitcoin blockchain with OpenTimestamps, together with a fingerprint of our full internal list, when the page goes live and with every update. Anyone can then check that everything we list existed by the time it was stamped.

Did you find this valuable? Tip the author!

Did you find this valuable? Tip the author!

Social Share Component

Download Blink

Start receiving and sending bitcoin now

Community