Circle and Tether froze about $318,000 in USDC and USDT linked to the Bitget hack
Circle and Tether froze $318,000 in stablecoins linked to the Bitget hack, but the attacker had already swapped the majority of the $387.5 million breach into Ether and other untouchable assets.

On Friday, September 25, Tether and Circle halted nearly $318,000 worth of stablecoins connected to the Bitget exchange breach, though the majority of the $387.5 million stolen had already been moved out. This event highlights both the usefulness and the limitations of asset freezes, which remain effective only until perpetrators transfer the funds away.
Circle’s terms for USDC permit the company to block transfers originating from specific wallets. Tether has similarly deployed its own controls when collaborating with law enforcement. However, neither organization possesses the ability to freeze Ether, meaning that once stolen capital is converted into ETH, it becomes impossible to freeze.
What issuers can and cannot freeze
Decrypt reported that Circle placed a ban on an address labeled “Bitget Exploiter 8” on Etherscan at 05:00 UTC on Friday. Roughly seven hours later, Tether added the same wallet to its USDT blacklist. Combined, they managed to freeze approximately 99,990 USDC and 218,023 USDT.
The targeted wallet still held nearly 170 accessible ETH. Meanwhile, blockchain trackers referenced by Decrypt indicated that additional addresses managed by the hacker contained over 63,000 ETH. The suspect appeared to move quickly, swapping tokens capable of being frozen into ETH ahead of further intervention.
From $351.6 million to $387.5 million
Bitget announced that its systems identified unauthorized transfers from a limited set of hot wallets on September 24 at 18:31 UTC. Initial estimates put the total losses at $351.6 million, but the figure was later revised upward to $387.5 million following a review of supplementary Zcash and TRON transfers that the first evaluation missed.
The exchange clarified that these adjustments reflected the complete scope of the original incident rather than a subsequent theft, noting that the situation had been contained. The impacted assets comprise XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX distributed across Ethereum alongside other EVM networks, the XRP Ledger, Zcash, and TRON.
Bitget indicated that a schedule for reopening fund withdrawals would be finalized by September 26 at 4:00 AM UTC.
A recovery network taking shape
According to Bitget, cold wallets remained unaffected, user account balances showed no discrepancies, and losses would be covered by Bitget’s User Protection Fund, which exceeds $464 million in value. SlowMist and Mandiant were brought onboard to assist with the inquiry.
Bitget also broadened its recovery initiatives by engaging outside participants. Its Recovery Bounty Program offers 5% for successfully frozen funds and another 5% for recovered amounts. Furthermore, Bitget encouraged industry partners to join the recovery effort. By disclosing hacker wallet addresses during public updates, the exchange underscored how security firms, issuers, and platforms must now cooperate when stolen capital moves across multiple chains.
Why stablecoin freezes keep coming up short
Velocity is the primary obstacle. A Cryptopolitan report from April noted that on-chain investigator ZachXBT alleged Circle was unable to intercept more than $420 million starting from 2022. Regarding Drift Protocol, Cryptopolitan highlighted that Circle delayed action for six hours while an attacker transferred over $223 million via its CCTP bridge, whereas Tether’s cross-chain USDT0 was frozen roughly 90 minutes post-hack.
Conversely, Tether has emphasized its enforcement track record. In April, the firm reported assisting U.S. authorities in freezing over $344 million worth of USDT. It also collaborates with more than 340 institutions spanning 65 nations, helping freeze over $4.4 billion in various assets overall. Paolo Ardoino, Tether’s CEO, stated that “USD₮ is not a haven for illicit activity.”
The Bitget security breach underscores the flaws inherent in these protocols: they function exclusively when stolen capital stays in tokens that issuers have the power to freeze.
Stablecoins are now wired into traditional markets
The stakes continue to rise as stablecoins grow more integrated into traditional financial systems. An International Monetary Fund paper suggests that a sudden shift in stablecoin demand will create short-term shocks for Treasury yields, spilling over into equities and cryptocurrency markets. Meanwhile, the OECD reported that the five largest stablecoins reached an estimated value of nearly $300 billion by March 2026, warning that tighter ties between crypto and legacy finance elevate risks related to cyber threats, consumer protection, and illicit finance.
PwC’s 2026 crypto regulation report points toward stricter oversight of stablecoins across over 50 jurisdictions, focusing primarily on reserves, redemption policies, governance, and operational resilience.
Regulatory urgency will only intensify as major security incidents persist. TRM Labs documented 207 hacks during the first half of 2026, generating $972 million in losses, with $643 million tied to North Korean financial activities. Concurrently, CoinGecko reported that total losses from January 2025 through July 2026 reached $3.63 billion across 245 incidents. Decrypt noted that North Korea’s Lazarus Group is suspected of orchestrating the Bitget assault, though unconfirmed.
Ultimately, the takeaway from the Bitget incident is not that stablecoin freezes failed outright; they succeeded, but solely regarding the funds still within reach. By the time the issuer stepped in, the bulk of the stolen assets had already been transferred. As stablecoins become deeply embedded in global economies, reaction speed may prove just as critical as the freeze mechanism itself.
If you’re reading this, you’re already ahead. Stay there with our newsletter.




Comments 0 responses