How the Bitget Hack Set a Precedent for Freezing Stolen Stablecoins Without a Legal Request
Key Takeaways
- •Circle and Tether blacklisted a wallet linked to the Bitget attacker within hours of the breach, freezing approximately $318,000 in USDC and USDT held at the address.
- •Bitget identified the attack on September 24, 2026, and later raised its estimate of affected assets to about $387.5 million, reflecting additional assets found on TRON and ZCash.
- •The response contrasts with the April 2026 Drift Protocol hack, when roughly $230 million in stolen USDC moved from Solana to Ethereum through Circle's Cross-Chain Transfer Protocol without being frozen.
- •Circle's prior stance was to freeze assets only when legally required, as demonstrated by the 2025 freezing of nearly $58 million in USDC tied to the LIBRA memecoin scam during a lawsuit led by Burwick Law.
- •The frozen amount represents only a small fraction of the stolen funds, since most assets, including more than 63,000 ETH across attacker-controlled addresses, cannot be frozen by stablecoin issuers.

Circle and Tether have moved to freeze stablecoins linked to the $387.5 million hack of crypto exchange Bitget, a response that marks a notable shift from the handling of the earlier Drift Protocol exploit and suggests the has become quicker to act once stolen funds enter centralized stablecoin infrastructure. The action came within hours of the breach being detected.
Rapid Blacklisting After the Bitget Breach
Circle blacklisted a wallet linked to the Bitget attacker at 0500 GMT, hours after the exchange detected unauthorized transfers from its hot wallets, the internet-connected wallets exchanges rely on for day-to-day deposits and withdrawals. According to on-chain data, the wallet contained approximately 99,990 USDC and 218,023 USDT, together worth roughly $318,000. Tether subsequently blacklisted the same address.
Blacklisting is the direct control stablecoin issuers hold over their own tokens: once an address is added to the list, transfers to or from it are blocked, immobilizing any USDC or USDT held at that address while leaving other assets there untouched.
The intervention followed Bitget's identification of the attack on September 24, 2026, and the launch of its effort to trace the stolen assets. The exchange later raised its estimate of affected assets to about $387.5 million, saying the higher figure reflected additional assets identified on networks including TRON and ZCash rather than further unauthorized transfers.
A Contrast With the Drift Protocol Exploit
The response stands in stark contrast to the April 2026 Drift Protocol hack, when approximately $230 million in stolen USDC was moved from Solana to Ethereum through Circle's Cross-Chain Transfer Protocol, the issuer's system for moving USDC natively between blockchains, in an episode described at the time as the largest DeFi exploit of 2026 so far. On-chain investigator ZachXBT publicly criticized Circle for failing to freeze the funds despite having had several hours to act. Circle's position then was that it freezes assets when legally required to do so.
That posture was evident in the freezing of nearly $58 million in USDC connected to the LIBRA memecoin scam in 2025, an example of Circle complying with such directives only when accompanied by a legal request. That freeze was reportedly carried out as part of an ongoing lawsuit spearheaded by the controversial law firm Burwick Law.
A Shift in Expectations
Against that backdrop, the Bitget incident offers an early indication that the Drift Protocol episode in April 2026 may have changed expectations around how quickly stablecoin issuers should respond to major hacks. Rather than waiting for the stolen assets to move further through the ecosystem, or for a legal or law enforcement request, Circle and Tether used their ability to blacklist their own tokens once an attacker-controlled address was identified.
The response nonetheless remains limited, and the frozen amount represents only a small fraction of the total funds. The ability to blacklist applies only to tokens the issuers themselves control; most of the stolen assets are held in ether and other cryptocurrencies that stablecoin issuers cannot freeze, with more than 63,000 ETH still tracked across attacker-controlled addresses.
Even so, the significance of the action lies less in the roughly $318,000 frozen in this case than in the speed and coordination of the response. The Drift hack exposed the consequences of allowing large amounts of stolen USDC to move across chains; the Bitget response shows stablecoin issuers acting more directly when they have the technical ability to stop funds.
How durable the shift proves may become clearer as Bitget's tracing effort progresses: whenever further attacker-controlled addresses are identified, whether Circle and Tether again freeze first, without a legal request, will indicate whether this episode marks a lasting change in issuer behavior.
For stablecoin companies, the precedent emerging from Drift appears to be becoming clearer: when a major hack occurs, speed can determine whether issuer-controlled assets remain recoverable or disappear deeper into the crypto ecosystem.