Blink Wallet's avatar
Blink Wallet
community@blink.sv
npub13ljn...cfhw
making bitcoin everyday money
Informe completo sobre el ataque del 19 de septiembre y una recompensa del 50% —hasta 3.3 BTC— sobre los fondos robados: Términos de la recompensa: El sábado 19 de septiembre un atacante usó una falla en nuestras herramientas administrativas para tomar el control de 35 cuentas de Blink y retirar unos 6.61 BTC de 24 de ellas. A las 11:39 UTC un cliente llamó a uno de nuestros ingenieros. Quince minutos después todo el servicio custodial estaba apagado. Esa misma noche la falla estaba cerrada y el servicio había vuelto. El jueves 24 de septiembre, cada cliente afectado tenía de vuelta su saldo exacto, en bitcoin y en dólares, pagado por los accionistas de Blink. Ningún cliente asume pérdida alguna. La culpa fue nuestra. No de Bitcoin, no de nuestros usuarios. A los 22 clientes a quienes les robaron bitcoin, y a las 3,817 personas cuyos datos de cuenta fueron consultados: lo sentimos. Cómo pasó: Desde octubre de 2023 hasta ese sábado, cualquier persona con una cuenta gratuita de Blink y un navegador podía darse a sí misma los poderes de nuestro equipo de soporte: cambiar el correo o el teléfono de cualquier cuenta, iniciar sesión como ese cliente y subir sus límites. Tres errores comunes en cómo nuestras herramientas administrativas revisaban permisos, uno encima del otro, en código que heredamos. Todo el equipo estaba ocupado migrando a decenas de miles de usuarios a la autocustodia bajo una nueva regulación. Un monitoreo pensado para detectar caídas del servicio no detectó a un administrador haciendo lo que ningún administrador debería hacer. Lo que no tocó: El dinero salió de nuestra billetera operativa. La mayoría de los fondos de los clientes está en almacenamiento en frío con firma múltiple, que nada en nuestras herramientas administrativas puede alcanzar. Las cuentas no custodiales nunca estuvieron en juego: no tenemos esas llaves. Lo que vio el atacante: También consultó datos de otras 3,817 cuentas; en algunos casos, un número de teléfono o un correo electrónico. No vio nombres, documentos de identidad, direcciones, contraseñas ni frases semilla. Escribimos a cada titular que pudimos contactar con el detalle exacto de lo que se vio. Lo que lo frenó: La autenticación de dos factores. El atacante inició sesión en nueve cuentas que la tenían activada e intentó dieciocho veces mover dinero. Cero pérdidas. Ninguna de las 24 cuentas vaciadas la tenía activada. Si haces una sola cosa después de leer esto: Configuración → Seguridad y privacidad → Autenticación de dos factores. Y actívala también en tu correo electrónico. Lo que cambiamos: La falla se cerró el mismo día y dos días después se agregó una tercera capa de protección. Las herramientas administrativas ya no están expuestas a internet. Las funciones que cambian el correo o el teléfono de un cliente están desactivadas para todos mientras las rediseñamos. Se revocaron todas las claves de API de los clientes. La billetera operativa guarda ahora una fracción de lo que guardaba. Las correcciones de seguridad se desarrollan en privado y se publican una vez desplegadas; el código sigue siendo abierto. Ya funciona un canal permanente para reportar problemas de seguridad, con recompensas de hasta 0.1 BTC por hallazgos críticos. Dónde está el dinero: Una parte sigue donde se retiró. Unos 5 BTC pasaron por un servicio de intercambio entre cadenas; una cantidad pequeña llegó a un exchange que está colaborando. Hay denuncias penales presentadas en El Salvador y en Próspera, los reguladores están notificados y hemos rastreado los fondos sin interrupción. No esperamos recuperar el dinero. Por eso ofrecemos una recompensa del 50%. Quien aporte la información que lleve a una recuperación recibe el 25% de lo que se recupere. Otro 25% de todo lo que se recupere va a Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera y las economías circulares que ellos elijan. Sin tope, sin fecha de vencimiento, y se paga solo con fondos que efectivamente vuelvan. Escribe a bounty@blinkbtc.com. Habríamos preferido mil veces destinar este dinero a la adopción de Bitcoin desde las bases que perderlo a manos de un ladrón. Debería darle vergüenza al atacante. Una cosa más: Ignora cualquier correo o SMS sobre este incidente que traiga un enlace: a los usuarios afectados les escribimos solo con mensajes dentro de la app de Blink. Nunca te pediremos tu PIN, tu contraseña, tu frase semilla ni un código de acceso. El informe completo tiene la cronología, el detalle técnico para quien opere código derivado del nuestro y los términos de la recompensa (enlaces al principio). Blink nació como la billetera de todos los días de un pequeño pueblo de playa donde la gente necesitaba dinero que funcionara. El 19 de septiembre, para 22 de nuestros clientes, no funcionó. Cada uno de ellos nos había confiado su dinero, que es lo único para lo que existe un custodio. A nuestros clientes, a los investigadores y exchanges que ayudaron en cuestión de horas, a los accionistas que respaldaron a la empresa sin dudarlo y al equipo que dejó todo un sábado: gracias. Recuperaremos la confianza como se ganó en El Zonte: estando presentes y logrando que los pagos pasen, todos los días.
Full post-mortem of the September 19 attack, and a 50% bounty — up to 3.3 BTC — on the stolen funds: Bounty terms: On Saturday September 19 an attacker used a flaw in our admin tools to take over 35 Blink accounts and withdraw about 6.61 BTC from 24 of them. A customer called one of our engineers at 11:39 UTC. Fifteen minutes later the whole custodial service was off. By that evening the hole was closed and the service was back. By Thursday September 24 every affected customer had their exact balance back, in bitcoin and in dollars, paid for by Blink's shareholders. No customer bears any loss. This was our fault. Not Bitcoin's, not our users'. To the 22 customers whose bitcoin was taken, and to the 3,817 people whose account details were looked up: we are sorry. How it happened: From October 2023 until that Saturday, anyone with a free Blink account and a web browser could give themselves the powers of our support staff: change the email or phone on any account, log in as that customer, raise their limits. Three unremarkable mistakes in how our admin tools checked permissions, stacked on top of each other, in code we inherited. The whole team was busy moving tens of thousands of users to self-custody under new regulation. Monitoring built to catch outages didn't catch an administrator doing things no administrator should. What it didn't touch: The money came out of our hot wallet. Most customer funds sit in multi-signature cold storage that nothing in our admin tools can reach. Non-custodial accounts were never in play: we don't hold those keys. What the attacker saw: They also read the details of 3,817 other accounts, in some cases a phone number or email address. Not names, not IDs, not addresses, not passwords, not seed phrases. We wrote to every holder we could reach, saying exactly what was seen. What stopped them: Two-factor authentication. The attacker logged in to nine accounts that had it on and tried eighteen times to move money. Zero loss. None of the 24 drained accounts had it on. If you take one thing from this post: Settings → Security and Privacy → Two-factor authentication. Then turn it on for your email too. What we changed: The flaw was fixed the same day and a third layer added two days later. The admin tools are off the public internet. The functions that change a customer's email or phone are switched off for everyone while we redesign them. All customer API keys were revoked. The hot wallet now holds a fraction of what it did. Security fixes are developed privately and published once deployed; the code stays open source. A standing security reporting channel is live, with rewards of up to 0.1 BTC for critical findings. Where the money is: Some still sits where it was withdrawn to. About 5 BTC has gone through a cross-chain swap service; a small amount reached an exchange that is cooperating. Criminal complaints are filed in El Salvador and Próspera, the regulators are notified, and we have traced the funds continuously. We are not expecting the money back. So we are putting a 50% bounty on it. Whoever provides the information that leads to a recovery gets 25% of what is recovered. Another 25% of anything recovered goes to Bitcoin Beach, Bitcoin Ekasi, Afribit Kibera and the circular economies they choose. No cap, no end date, paid only out of funds that actually come back. Write to bounty@blinkbtc.com. We would far rather have spent this money on grassroots Bitcoin adoption than lost it to a thief. Shame on the attacker. One more thing: Ignore any email or SMS about this incident that contains a link: we contacted affected users only through messages in the Blink app. We will never ask for your PIN, password, seed phrase or a login code. The full post-mortem has the timeline, the technical detail for anyone running code derived from ours, and the bounty terms (links at the top).
Blink Wallet's avatar
Blink Wallet 3 weeks ago
Accepting Bitcoin is one thing. Paying your staff in it is another. Bitcoin Ekasi moved all its assistants' salaries into sats this week — Bitcoin at the start of the local money cycle, not just the checkout. In Santo Domingo, a burger shop paid a bread maker in sats, who used those same sats to send a remittance abroad: one payment doing a sale, a wage and a cross-border transfer with no bank in between. Reliability stayed part of the story. The Liquid sidechain reported ~$320M drained, then saw most of it returned on-chain a day later, minus a haircut — a reminder that partial recovery isn't the same as being made whole. And BTCPay shipped another security-driven release, trading some convenience for a smaller attack surface.
Blink Wallet's avatar
Blink Wallet 2 months ago
Accepting Bitcoin just got easier: the new BTCPay plugin turns a Blink Lightning address into a full merchant setup — no node, no API key, your keys. Lightning Labs ships Wavelength, pooled sats buy a cow, and a town in El Salvador pays for laundry, juice, and coffee in bitcoin — this week's brief.
Blink Wallet's avatar
Blink Wallet 2 months ago
Accept Bitcoin on BTCPayserver with Blink — now with non-custodial accounts. Connect with just your Blink lightning address, keep custody of your funds, and skip the technical hassle. See it work in under 5 minutes Get started → blink.sv/btcpay Plugin → Docs →
Blink Wallet's avatar
Blink Wallet 4 months ago
Blink Wallet's avatar
Blink Wallet 11 months ago
When you can pay for everything with bitcoin - what changes next?
Blink Wallet's avatar
Blink Wallet 1 year ago
New post! ​Inflation is a hidden tax on everyone. Our new guide breaks down the "Cantillon Effect" and why Bitcoin is the peaceful revolution against the money printer. ​Read more: blink.sv/blog/inflation
Blink Wallet's avatar
Blink Wallet 1 year ago
"I use Blink for onboarding newbies, but it's a turn-off when SMS doesn't arrive instantly... 😪" Say no more, fam 🧑‍🔧 With the latest version of Blink, it's possible to add phone number later, so onboarding is Lightning⚡️ fast!
Blink Wallet's avatar
Blink Wallet 1 year ago
Lightning? ⚡️ Bitcoiners asked for it. We built it. Everybody uses it. The consequence? Fast, low-cost transactions. 🎉 But no sleeping. Let's keep on building 🚀 image
↑