Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist
The stablecoin issuer blacklisted a wallet holding about $318,000 in USDT and USDC. Most of the stolen funds sit in ether, which can't be frozen.
Circle and Tether have frozen stablecoins in a wallet linked to Thursday's $351.6 million Bitget hack, though the amount is a small fraction of the total.
Circle blacklisted the address, which Etherscan labels "Bitget Exploiter 8," at 05:00 UTC Friday, onchain data shows. The wallet holds about 170.47 ETH, 218,023 USDT and 99,990 USDC. Blockchain security firm MistTrack said Tether has since banned the wallet too.
That leaves roughly $318,000 in stablecoins stuck. MistTrack's tracker shows other exploiter addresses still holding more than 63,000 ETH, which no issuer can freeze.
Bitget CEO Gracy Chen said attackers compromised a backend system in the exchange's wallet infrastructure, spoofed transaction data and triggered its authorization process to move funds out. She ruled out a private key compromise. Chen said Bitget's user protection fund, which holds over $464 million, covers the loss.
Circle's quick action contrasts with its response to April's $285 million Drift hack. In that case, the attacker moved about $232 million in USDC from Solana to Ethereum using Circle's own cross-chain transfer protocol. Critics including ZachXBT said Circle could have moved faster to blacklist wallets and freeze funds. Circle said it freezes assets when legally required.
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Asanat Analysis — Why it matters
Circle and Tether's coordinated wallet blacklisting demonstrates the practical limits of stablecoin-based asset recovery. While freezing $318k in USDT/USDC signals issuer willingness to enforce compliance, the excerpt's emphasis that 'most stolen funds sit in ether' reveals a critical constraint: native blockchain assets lack built-in pause mechanisms. This asymmetry—stablecoins are freezable, ETH is not—creates perverse incentives for hackers to immediately swap into non-custodial assets, rendering issuer-level controls obsolete.
The Bitget heist response illustrates why institutional DeFi security remains a regulatory and technical frontier. Exchanges hold billions in customer assets yet lack the cryptographic guarantees that on-chain protocols provide. The incident signals growing pressure on platforms to implement better key management, but also the uncomfortable truth that even rapid issuer intervention recovers only a fraction of stolen funds. This may accelerate demand for on-chain custody solutions and non-custodial trading infrastructure, where no single party controls freeze capabilities.
Operationally, the coordination between Circle and Tether shows stablecoin issuers treating blacklisting as part of their compliance toolkit—a shift from early crypto-era neutrality. Whether this sets precedent for other hacks or remains case-specific depends on regulatory signaling and victim status (institutional vs. retail).