Key Highlights
- Blink Wallet paused services on September 19 while investigating a security incident.
- An attacker accessed a limited number of custodial accounts and withdrew funds, according to Blink.
- The company said the large majority of funds remain secure.
Bitcoin wallet provider Blink paused its services on September 19, 2026, while investigating a security incident. An attacker accessed a limited number of custodial accounts and withdrew funds, according to a statement posted by the company on the social media platform X. The large majority of funds remain secure, the statement said. Non-custodial wallets are not affected.
In an X post on September 19, Blink stated that services have been paused pending the investigation. The company provided no further details on the number of affected accounts, the amount withdrawn, or how the attacker gained access, in the initial statement.
Recent DeFi and protocol Incidents
The Blink pause occurred against a backdrop of several publicly reported security incidents in mid-September 2026. Nostra Finance, a lending, swap, and bridge protocol built on the Starknet Layer 2 network, paused its money market on September 17 after a manipulated price feed for its native NSTR token allowed a single account to borrow approximately $3.5 million in digital assets against inflated collateral.
The exploit forced the protocol to disable lending, borrowing, withdrawals, and liquidations while the team reconciles pool balances and traces the funds. Nostra said the final loss and any recoveries are not yet known. In a statement posted on X at 13:28 UTC on September 17, the team reported that a manipulated NSTR oracle price enabled one account to treat its NSTR holdings as inflated collateral and borrow assets including ETH, STRK, USDC, USDT, WBTC, and DAIv1.
Separately, Blockaid’s exploit detection system identified an attack on older Flamincome contracts associated with FlamingoFinance, a decentralized finance platform.
According to Blockaid’s public report published on September 16, an attacker used a flash loan of approximately $18 million in USDT, inflated the share price of the VaultYUSDT by staking USDP liquidity-provider tokens into a strategy contract, and then redeemed liquid aUSDT. The attacker’s profit stood at roughly $345,900 in USDT at the time of the disclosure.
Broader September 1–7 exploit totals
As previously reported by The Crypto Times, cryptocurrency exploits recorded between September 1 and September 7, 2026, totaled roughly $322 million, based on a consolidated review of project statements, on-chain investigators, and security-firm alerts issued at the time of each incident. The week was dominated by a single event on the Bitcoin sidechain Liquid Network, which alone accounted for more than 99% of the reported figure.
The remainder was spread across four confirmed on-chain drains on Ethereum, BNB Chain, and the XRP Ledger. The totals reflect figures reported at the time of each incident and do not include derivative liquidations, malware that only uses public blockchains for command-and-control data, or exploits that began earlier and only received follow-up updates during the week.
Blink’s statement emphasized that the large majority of funds under its custody remain secure and that non-custodial wallets fall outside the scope of the incident. The company provided no timeline for the resumption of services or additional technical details in its initial post.
Also Read: Peter Schiff Calls Bitcoin Rally After SEC Tokenized-Stock Action Illogical
