Circle and Tether froze nearly $318,000 in stablecoins related to the Bitget exchange hack on September 25, but the action highlighted both the utility and limitations of asset freezes. By the time the companies acted, the attacker had already converted most of the $387.5 million stolen in the breach into Ether and other cryptocurrencies that cannot be frozen by stablecoin issuers.
Circle banned an address labeled "Bitget Exploiter 8" on Etherscan at 05:00 UTC on Friday, freezing approximately 99,990 USDC. Tether added the same wallet to its USDT blacklist roughly seven hours later, freezing an additional 218,023 USDT. However, the same address retained nearly 170 ETH in accessible funds, while blockchain trackers showed other addresses controlled by the hacker held more than 63,000 ETH.
The Speed Problem
The core issue limiting the effectiveness of stablecoin freezes is speed. According to previous reporting, Circle has been unable to intercept more than $420 million in stolen funds since 2022. In the Drift Protocol incident, Circle failed to act for six hours while an attacker transferred over $223 million using its CCTP bridge.
Tether has emphasized its enforcement record, reporting in April that it had assisted U.S. authorities in freezing over $344 million in USDT and has worked with more than 340 institutions across 65 countries to freeze over $4.4 billion in various assets.
The Bitget Breach Scope
Bitget initially reported the breach at $351.6 million on September 24 at 18:31 UTC but later revised the total to $387.5 million after accounting for additional Zcash and TRON transfers that the first assessment overlooked. The exchange stated the revision reflected the full scope of the original breach, not new theft, and that the situation had been contained.
Affected assets included XRP, ETH, USDT, USDC, ZEC, BNB, AVAX, TRX, and other tokens across multiple blockchains. Bitget indicated that withdrawal schedules would be confirmed by September 26 at 4:00 AM UTC.
Recovery Efforts
Bitget stated that cold wallets remained unharmed and user account holdings showed no discrepancies. The exchange said losses would be compensated through its User Protection Fund, valued at more than $464 million. Mandiant and SlowMist were engaged to assist with the investigation.
Bitget launched a Recovery Bounty Program offering 5% of successfully frozen funds and 5% of recovered amounts to participants, and called on industry partners to join the recovery effort by sharing information about hacker addresses.
Broader Implications
As stablecoins become more integrated into traditional finance, the risks expand. According to an International Monetary Fund paper, shocks in stablecoin demand could impact Treasury yields and create spillover effects into crypto and equities markets. The OECD noted that the five largest stablecoins were estimated to reach nearly $300 billion by March 2026 and warned that closer ties between crypto and traditional finance increase cyber, consumer protection, and illicit finance risks.
A 2026 crypto regulation report by PwC projected stricter stablecoin regulations in more than 50 jurisdictions, focusing on reserves, redemption, governance, and operational resilience. These regulatory pressures are expected to intensify as major security breaches continue to occur.


