Blink Wallet has disclosed a security incident in which attackers transferred funds from dozens of custodial accounts. The affected accounts were held under the platform’s custody, but the total loss, timing of the breach and technical route used by the attackers have not yet been fully disclosed.
The incident highlights the different risk profiles of custodial and self-custodied crypto wallets. In a custodial arrangement, the platform typically manages account keys or assets while users rely on its systems for deposits, transfers and withdrawals. If account permissions, internal systems or connected services are compromised, the impact can extend beyond an individual user, depending on the access rights of the affected components.
Dozens of custodial accounts affected
The information currently available indicates that a “small number of dozens” of Blink Wallet’s custodial accounts were affected, with funds transferred out of those accounts. The platform has not provided an exact account count, disclosed the assets involved or published the value and final destination of the on-chain transactions.
The reference to dozens of accounts does not mean that all Blink Wallet users were affected. The scope of the incident will depend on the results of the platform’s technical investigation, on-chain address tracking and reconciliation of the affected accounts. Account numbers alone are also insufficient to estimate the total financial loss, as balances may have varied significantly from one account to another.
Losses and attack method remain unknown
Key unanswered questions include how the attackers obtained account access, whether the transferred assets were concentrated on a particular blockchain, whether Blink Wallet suspended related operations and whether affected users will be compensated. The answers will shape users’ assessment of whether the assets can be recovered and how the platform will handle the incident.
The available information does not establish whether the breach involved a smart-contract vulnerability, failed authentication, misuse of internal permissions or a compromise of a third-party service. Until the investigation produces findings, the incident cannot be attributed to a specific technical cause. Blockchain records may help trace the movement of funds, but traceability does not guarantee recovery.
Custody controls and user access under scrutiny
The Blink Wallet incident has put renewed attention on asset segregation, permission controls and security response procedures at custodial wallet providers. With a non-custodial wallet, users generally hold their own private keys and the platform cannot directly control the assets. A custodial wallet, by contrast, requires the provider to maintain account infrastructure, key-management procedures and transaction approval controls. The two models offer different levels of convenience and place control-related risks in different parts of the system.
For affected users, the immediate questions are whether their accounts have been included in the investigation, whether the relevant assets have been frozen or traced, and whether withdrawals, transfers or account access have been temporarily restricted. Blink Wallet will also need to explain how affected accounts are being identified, provide a timeline of the incident and set out any recovery or compensation arrangements.
The incident occurred in September 2026, and Blink Wallet has yet to publish the results of its technical investigation and funds reconciliation. Until the loss amount, attack route and user-response plan are clarified, the confirmed facts remain limited: funds were transferred from approximately dozens of custodial accounts, while the full impact of the incident is still undetermined.