24 accounts hacked, 6.61 BTC stolen; Blink releases attack post-mortem and offers a bounty of up to 3.3 BTC
Odaily News: According to Bitcoin News monitoring, Blink has released a full post-mortem of the September 19 attack: the attack resulted in the theft of a total of 6.61 BTC from 24 customer accounts. The company stated that the vulnerability had existed since October 2023, and any user with a free Blink account could potentially exploit it to gain customer-service-level privileges, take over customer accounts, and raise withdrawal limits. The attacker also obtained partial information from 3,817 accounts, including some phone numbers and email addresses; names, identity documents, addresses, passwords, and seed phrases were not leaked.
None of the 24 stolen accounts had two-factor authentication enabled. The attacker attempted 18 withdrawals from 9 accounts protected by two-factor authentication, all of which failed. Blink shareholders have fully reimbursed all affected customers.
About 5 of the stolen BTC were subsequently transferred through a cross-chain swap service. Blink is now offering a recovery bounty of up to approximately 3.3 BTC, with half of any successfully recovered funds to be distributed to those who provide valid leads and to the Bitcoin circular economy.
