NewsCryptoCircle and Tether Freeze $318,000 in Stablecoins Tied to Bitget Hack as Bulk of Stolen Funds Slips Away

Circle and Tether Freeze $318,000 in Stablecoins Tied to Bitget Hack as Bulk of Stolen Funds Slips Away

Author: Decrypt·

Key Takeaways

  • •Circle and Tether froze approximately $318,000 in stablecoins—about 99,990 USDC and 218,023 USDT—by blacklisting a wallet tied to the Bitget hack at the contract level.
  • •Circle blacklisted the address, labeled "Bitget Exploiter 8" on Etherscan, at 05:00 UTC on Friday, and Tether added the same address to the USDT blacklist roughly seven hours later.
  • •Because each issuer's blacklist applies only to its own token, freezing a wallet holding both USDC and USDT required coordinated action from both.
  • •The attacker converted most freezable assets into ether before the intervention, and exploiter-linked addresses still hold more than 63,000 ETH—plus about 170 ETH in the flagged wallet—that no issuer can freeze.
  • •The breach, with early loss estimates of roughly $387 million and possible links to North Korea's Lazarus Group, stemmed from a compromised backend system in Bitget's wallet infrastructure, and the exchange's user protection fund of more than $464 million will cover losses.
Circle and Tether Freeze $318,000 in Stablecoins Tied to Bitget Hack as Bulk of Stolen Funds Slips Away

Circle and Tether have frozen a wallet tied to the hack of crypto exchange Bitget, blacklisting roughly $318,000 in stablecoins at the contract level. The coordinated action cut the attacker off from a portion of the haul, but the bulk of the stolen funds had already been converted beyond the issuers' reach.

Blockchain data shows Circle blacklisted the address, labeled "Bitget Exploiter 8" on Etherscan, at 05:00 UTC on Friday, using the freeze function built into its USDC token contract. Roughly seven hours later, Tether followed suit, with a signer confirming a transaction on its multisig wallet that added the same address to USDT's blacklist. Together, the two moves locked approximately 99,990 USDC and 218,023 USDT in place. Because each issuer's blacklist applies only to its own token, freezing a wallet that holds both USDC and USDT requires both companies to act in tandem—neither issuer could have locked the full balance alone.

The wallet also held around 170 ETH, and that portion remains untouched. The episode underscores the core limitation of stablecoin freezes: issuers can blacklist their own tokens at the contract level, but no one can freeze Ethereum itself. Tokens on a blacklist cannot be moved by their holder, while ether in a flagged address remains fully under the attacker's control.

That gap explains why so little was recovered. The attacker appears to have raced to convert freezable assets into ETH before the issuers intervened, consolidating stolen tokens into fresh wallets and swapping stablecoins out within minutes. Blockchain trackers indicate that other exploiter-linked addresses still hold more than 63,000 ETH that no issuer has the authority to touch—balances that on-chain analysts are expected to keep monitoring for any sign of further movement.

The freezes amount to a small dent in one of the year's largest exchange breaches. The Bitget hack drained hundreds of millions of dollars, with early estimates pegging losses at roughly $387 million, and analysts have pointed to North Korea's Lazarus Group as a possible culprit—a group that security researchers and Western authorities have repeatedly tied to some of the largest cryptocurrency thefts on record.

Bitget CEO Gracy Chen has said the attackers compromised a backend system within the exchange's wallet infrastructure, spoofing transaction data to trigger unauthorized transfers, while ruling out a private-key compromise. The exchange has said a user protection fund holding more than $464 million will cover losses.

The rapid blacklisting drew notice as a faster response than in some past incidents, though it also renewed a long-running debate about the centralized control that stablecoin issuers wield over assets often described as permissionless—a power demonstrated when two of the sector's largest issuers moved within hours of each other against the same address.