Circle and Tether Freeze Stablecoins Tied to Bitget Hack—But Most Funds Slip Away
Circle and Tether blacklisted a wallet linked to the Bitget exchange hack, freezing about 99,990 USDC and 218,023 USDT (roughly $318,000) at the contract level. The attacker had already converted most stolen funds into Ethereum, leaving about 170 ETH in the frozen wallet and other exploiter addresses holding over 63,000 ETH beyond issuers' reach.

Why It Matters
The action shows how stablecoin issuers can use contract-level controls to block token movements quickly, but also highlights the limits of that power when attackers convert assets into base-layer cryptocurrencies like ETH that issuers cannot freeze.
Key Facts
- USDC frozen: ~99,990 USDC
- USDT frozen: 218,023 USDT
- Approximate value frozen: ~$318,000
- Time of Circle action: 05:00 UTC Friday
- Tether action: Approximately seven hours after Circle via multisig
Circle and Tether have used built-in blacklist features on their token contracts to freeze stablecoins held in a wallet tied to the large Bitget exchange hack. Blockchain records show Circle blacklisted the address labeled "Bitget Exploiter 8" at 05:00 UTC on Friday. Hours later, a Tether multisig signer confirmed a transaction adding the same address to USDT's blacklist.
Together those steps locked about 99,990 USDC and 218,023 USDT, a total of roughly $318,000. However, the wallet also held about 170 ETH, which remained unaffected because issuers can only freeze their own tokens at the contract level — they have no authority to freeze Ethereum itself.
Trackers and on-chain data indicate the attacker rapidly converted freezable stablecoins into ETH and moved funds through fresh addresses within minutes, leaving the freeze actions able to capture only a small portion of the stolen assets. Other exploiter-linked addresses continue to hold more than 63,000 ETH that are outside the reach of stablecoin issuers.
The blacklisting represents a limited recovery in a breach estimated at about $387 million. Bitget has attributed the incident to a compromise of a backend wallet infrastructure system rather than a private-key leak, and said a user protection fund of over $464 million will cover losses. Analysts have suggested a possible link to the Lazarus Group, a North Korea-linked hacking collective.
Keep Reading
Bitget Raises Hack Estimate To $387.5 Million As Token Accounting Widens
SEC Staff Clarifies Token Buybacks and Liquid Staking in New FAQs
