BLOG |
Bitcoin LN 101
Self-custody is a partnership: we make sure your keys are born safely inside your phone's secure hardware, and you keep the 12 words somewhere only you can reach.
A while ago we published Know Your Custodian, explaining how we keep your bitcoin safe when Blink holds it for you. Many of you have since chosen the other path: a non-custodial Blink account, where you hold the keys and Blink never touches your funds. That freedom comes with a fair question — "if it's all on my phone now, how do I know it was set up safely?" This post answers that, in plain language.
With a non-custodial account, your wallet isn't an entry in Blink's database — it's a set of 12 secret words that live only on your phone. Those 12 words are your wallet. Anyone who has them controls the money; anyone who doesn't, can't. Blink's servers never see them, never store them, and can't move your bitcoin for you. You hold the keys.
That's a lot of power to put in your pocket. So the most important moment in the whole experience is the very first one: the instant those 12 words are created. If they're created well, your wallet is safe. Get that step right, and everything else follows.
The short version: Our engineering team reviewed exactly how your recovery phrase is created inside the Blink app. The randomness it's built from comes only from your phone's dedicated security hardware — the same vault-grade randomness your phone uses to protect banking apps and its own lock screen. Every bit of that randomness reaches your phrase, nothing is weakened or shortcut, and if secure randomness were ever unavailable, the app refuses to create a wallet rather than guess. Your phrase is then stored in your phone's protected keychain, never in the cloud unless you choose to back it up.
Think of creating a wallet like flipping a coin 128 times and writing down the result. That string of heads and tails gets turned into your 12 words. The reason nobody can ever guess your wallet is simple: there are more possible outcomes than there are atoms in a mountain — 340 billion billion billion billion of them (that's 34 followed by 37 zeros). Even a computer testing trillions of guesses every second would run out of time long before the universe did.
But that promise only holds if the "coin flips" are genuinely unpredictable. If the coin is secretly weighted — if the randomness is fake — then the number of real possibilities shrinks, and a wallet can become guessable. This is the one thing that absolutely has to be done right, and it's where we focused our review.
In July 2026, security researchers at Block published findings on a critical flaw in a hardware wallet called COLDCARD (read their report). The device's firmware could fall back to a predictable source of randomness instead of a truly unpredictable one — meaning some keys were built from a guessable pattern rather than genuine chance. That made affected wallets vulnerable, and users lost funds. This was not a cosmetic bug or a minor oversight; it is a fundamental failure of the one job a wallet cannot get wrong, and it went unnoticed for years.
The lesson for everyone building wallets is this: the math behind Bitcoin is rock-solid, but wallets don't fail at the math — they fail at the plumbing. A single wrong connection between the app and the phone's randomness can quietly undermine everything. Failures like this are exactly why the way a wallet creates its keys deserves close scrutiny — and why we want to show you, openly, how Blink does it.
Reviewing our security isn't something we do only when the news demands it — it's part of how Blink is built. But a moment like this is a good opportunity to walk you through exactly what happens when you tap "create wallet." Here it is, in plain terms — and every point below is something our engineers verify against the actual code, not a marketing promise:
The bottom line: your non-custodial Blink wallet is created from genuine, hardware-grade randomness, with no shortcuts, no hidden fallback, and no way for Blink — or anyone else — to see your words as they're made.
Self-custody is a partnership. Here's the honest split of who does what:
Choosing self-custody doesn't mean you're on your own. It means you hold the keys — and we build the safest possible place for those keys to be born and to live. We got the hard part right so you can focus on the simple part: guarding your 12 words. Your bitcoin, your keys, your peace of mind.
Start receiving and sending bitcoin now