Circle and Tether freeze ~$318k in stablecoins tied to Bitget hack; most of the haul sits…

security⚖️ NeutralSignal 81$USDC$USDT$ETH

⏱ 2 min read

Issuer blacklists worked quickly but late—about 0.08% of an estimated $387m breach was frozen as the attacker shifted value into non-freezable ETH.


Circle and Tether froze a small slice of funds tied to the Bitget exchange hack, blacklisting roughly 99,990 USDC and 218,023 USDT—about $318,000—while most of the stolen assets had already been moved into Ethereum.

According to the supplied blockchain details, Circle blacklisted an address labeled “Bitget Exploiter 8” on Etherscan at around 05:00 UTC Friday using USDC’s contract-level freeze function. Roughly seven hours later, Tether’s multisig added the same address to USDT’s blacklist. The wallet also held around 170 ETH, which remained unaffected.

The mechanism—and its limit

Stablecoin issuers can immobilize their own tokens by adding addresses to a blacklist at the contract level; they cannot freeze base-layer assets like ETH. Trackers indicate other exploiter-linked addresses still hold more than 63,000 ETH—funds no issuer can directly control. The attacker appears to have converted freezable balances into ETH before the blacklists took effect.

Calculation: the ~$318,000 in frozen USDC/USDT versus an estimated $387 million breach implies recovery on the order of 0.08%. That gap illustrates why time-to-freeze, and the window before attackers swap into non-freezable assets, is the decisive variable for containment.

$ETH
▲ 0.25%
$2,693

Why it matters

Issuer blacklists are a useful chokepoint only if triggered before conversion. Once value sits in ETH, on-chain freezes lose leverage and recovery options narrow to monitoring and potential legal action rather than direct asset control.

Limitations and attribution

Early estimates put the breach near $387 million, and analysts have suggested North Korea’s Lazarus Group as a possible culprit; neither the total nor the attribution is confirmed here. Bitget’s CEO has said attackers compromised a backend system in the exchange’s wallet infrastructure, spoofing transaction data and ruling out a private-key compromise. Bitget says a user protection fund holding more than $464 million will cover losses.

What to watch next

• Any extension of blacklists to additional addresses holding exploiter-linked stablecoins.
• Movement of the 63k+ ETH and whether it consolidates or disperses across fresh wallets.
• Bitget’s disclosure on incident forensics and any changes to wallet infrastructure and monitoring.
• Actual deployment of Bitget’s $464 million protection fund to reimburse users.


This content is for informational purposes only and does not constitute financial advice.

🧠 HafidWatch Take

The freezes captured only about $318,000 of the estimated $387 million breach, roughly 0.08%, because the attacker quickly converted freezable assets into ETH, which issuers cannot freeze. This highlights the critical role of time-to-freeze and exchange controls that can interrupt in-flight swaps. While stablecoin blacklist powers serve as useful chokepoints, their effectiveness depends on speed and asset composition; once value moves into ETH, recovery options diminish significantly. The focus now is on whether any remaining exploiter-linked stablecoins can be identified before further conversions and whether Bitget enhances its internal controls and monitoring to narrow the window attackers have to move assets into non-freezable forms.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.