Odaily Planet Daily reports, according to Bitcoin News monitoring, Blink has released a full post-mortem of the September 19 attack: the breach resulted in the theft of 6.61 BTC from 24 customer accounts. The company stated that the vulnerability existed since October 2023, allowing any user with a free Blink account to gain customer support-level privileges, take over customer accounts, and increase withdrawal limits. The attackers also obtained partial information from 3,817 accounts, including some phone numbers and email addresses; names, identification documents, addresses, passwords, and seed phrases were not compromised.
None of the 24 compromised accounts had two-factor authentication enabled. The attacker attempted 18 withdrawal requests from 9 accounts protected by two-factor authentication, all of which failed. Blink shareholders have fully reimbursed all affected customers.
Approximately 5 stolen BTC were subsequently transferred via a cross-chain exchange service. Blink is now offering a reward of up to 3.3 BTC for the recovery of funds, with half of the recovered amount allocated to those providing valid leads and the Bitcoin circular economy.

