What to Know
- Circle and Tether froze stablecoins in a wallet linked to Thursday's $351.6 million Bitget hack.
- The blacklisted wallet holds about 218,023 USDT and 99,990 USDC, leaving roughly $318,000 in stablecoins stuck.
- The same wallet also holds about 170.47 ETH.
- Onchain data shows Circle blacklisted the address labeled Bitget Exploiter 8 at 05:00 UTC Friday.
- Blockchain security firm MistTrack said Tether has since banned the wallet as well.
- Other exploiter addresses still hold more than 63,000 ETH, which no stablecoin issuer can freeze.
- Bitget CEO Gracy Chen said attackers compromised a backend system in the exchange's wallet infrastructure, spoofed transaction data and triggered authorization to move funds out.
- Chen ruled out a private key compromise and said Bitget's user protection fund, which holds over $464 million, covers the loss.
- Circle's faster response follows criticism over its handling of April's $285 million Drift hack, when about $232 million in stolen USDC moved from Solana to Ethereum through Circle's own transfer infrastructure.
Stablecoin Issuers Move Against Bitget Exploiter Wallet
Circle and Tether have taken action against a wallet connected to the $351.6 million Bitget hack, freezing stablecoins that investigators and onchain watchers have linked to the exploit. The action blocks movement of about 218,023 USDT and 99,990 USDC held in the wallet, leaving roughly $318,000 in stablecoin value unable to move through normal token transfer functions.
The address, labeled by Etherscan as Bitget Exploiter 8, was blacklisted by Circle at 05:00 UTC Friday, according to onchain data. Blockchain security firm MistTrack later said Tether had also banned the wallet. The freeze is significant because it shows that stablecoin issuers can intervene when tokens under their control are tied to major thefts. However, the move captures only a narrow slice of the broader proceeds from the Bitget incident.
The same address also holds about 170.47 ETH. Unlike centralized stablecoins such as USDT and USDC, ether is not issued by a company with the ability to blacklist a particular wallet or stop token movement at the contract level. That distinction is now central to the aftermath of the Bitget breach, because MistTrack's tracker shows other exploiter addresses still holding more than 63,000 ETH. Those funds remain beyond the freezing powers available to Circle, Tether or any other stablecoin issuer.
Why the Freeze Captures Only a Small Share of the Hack
The stablecoin freeze is a notable containment step, but it does not materially reverse the scale of the Bitget loss. The hack totaled $351.6 million, while the frozen USDT and USDC add up to roughly $318,000. That gap underscores a recurring challenge in crypto incident response: funds can be split across asset types, chains and addresses faster than issuers, exchanges and security teams can coordinate a response.
Stablecoins such as USDT and USDC are designed to function on public blockchains, but their issuers retain administrative controls that can blacklist addresses under certain circumstances. When an address is blacklisted, the affected tokens cannot be transferred from that wallet. This capability has become an important tool in high profile exploit investigations, especially when stolen funds pass through assets controlled by regulated issuers.
Ether operates differently. ETH is native to Ethereum and does not depend on a centralized issuer contract that can selectively freeze balances. Once stolen funds are in ETH, enforcement options shift away from token level controls and toward exchange monitoring, tracing, possible recovery negotiations and law enforcement coordination. That is why the more than 63,000 ETH held in other exploiter addresses remains central to the unresolved portion of the Bitget incident.
Bitget Says Backend Wallet Infrastructure Was Targeted
Bitget CEO Gracy Chen said attackers compromised a backend system in the exchange's wallet infrastructure. She said the attackers spoofed transaction data and triggered the exchange's authorization process to move funds out. That explanation points to an infrastructure level exploit rather than a direct failure of the exchange's private key custody.
Chen also ruled out a private key compromise. That distinction matters because private key theft can imply that attackers gained direct signing control over wallets, while a backend system compromise can suggest that attackers manipulated internal processes or transaction flows without obtaining the key material itself. Both outcomes can be severe, but the operational implications for remediation and future security reviews can differ sharply.
Chen said Bitget's user protection fund, which holds over $464 million, covers the loss. For users, that statement is meant to address concerns about whether the exchange can absorb the damage without passing losses to customers. In the immediate aftermath of a large exchange exploit, user confidence often depends on whether the platform can demonstrate both technical containment and financial coverage.
Circle's Response Draws Comparisons With the Drift Hack
Circle's quick action in the Bitget case stands in contrast to criticism the company faced after April's $285 million Drift hack. In that incident, the attacker moved about $232 million in USDC from Solana to Ethereum using Circle's own cross chain transfer protocol. Critics, including ZachXBT, said Circle could have acted faster to blacklist wallets and freeze funds before they moved further through the ecosystem.
Circle has said it freezes assets when legally required. The tension around these cases reflects a broader debate over how centralized stablecoin issuers should respond when stolen funds are in motion. Rapid freezes can preserve value for victims and reduce the incentive for hackers to move through stablecoins. At the same time, issuers typically operate within legal and compliance frameworks that may require clear thresholds before intervention.
The Bitget response may be viewed by market participants as evidence that stablecoin issuers are becoming more alert to fast moving exploits. Still, the small amount frozen also shows the limits of issuer intervention when stolen funds quickly concentrate in assets that lack a centralized freeze function. The presence of more than 63,000 ETH in other exploiter addresses means tracing and monitoring will remain important even after the USDT and USDC freeze.
What the Incident Shows About Crypto Security
The Bitget hack highlights how modern crypto attacks increasingly target operational systems rather than simply attempting to steal private keys. If attackers can manipulate backend data, transaction authorization flows or internal controls, they may be able to trigger outward transfers even without taking direct possession of signing keys. That makes exchange security a multilayered problem involving custody design, infrastructure hardening, access controls, transaction validation and real time anomaly detection.
It also shows why onchain transparency is both helpful and incomplete. Investigators, exchanges and security firms can follow wallets, identify balances and flag addresses in near real time. Public labeling, such as the Bitget Exploiter 8 tag, can help the market track suspicious funds. But visibility does not automatically produce recovery. When funds sit in ETH, public tracking can reveal location without providing a direct mechanism to freeze the balance.
Stablecoin freezes remain one of the few immediate onchain containment tools available after major hacks. When stolen value remains in USDT or USDC, issuers can prevent further movement from a known wallet. That can buy time for victims, investigators and legal authorities. Yet the tool is most effective only when the stolen funds have not already been converted or moved into assets outside issuer control.
Market Impact and Next Steps
For the crypto market, the Bitget exploit is another reminder that centralized exchange security remains a critical point of trust. Exchanges manage complex wallet infrastructure, internal authorization systems and customer facing services, all of which must withstand attempts to manipulate transaction flows. A large loss can quickly become a market confidence issue, even when the exchange says a protection fund is sufficient to cover the damage.
In the near term, attention is likely to remain on the exploiter wallets holding more than 63,000 ETH and on any movement from those addresses. If funds are sent to exchanges, mixers, bridges or other services, monitoring teams may attempt to flag the transactions and coordinate responses. However, because ETH itself cannot be frozen at the issuer level, any recovery path will likely depend on successful tracing, platform cooperation or external enforcement actions.
FXCOINZ will continue treating the incident as a major exchange security story rather than a simple stablecoin freeze. Circle and Tether's intervention trapped a defined portion of USDT and USDC, but the broader case remains unresolved as long as the majority of stolen value remains in assets that cannot be blacklisted by an issuer.
Frequently Asked Questions (FAQs)
What did Circle and Tether freeze?
Circle and Tether froze stablecoins in a wallet linked to the Bitget hack. The wallet holds about 218,023 USDT and 99,990 USDC, leaving roughly $318,000 in stablecoins stuck.
How large was the Bitget hack?
The Bitget hack totaled $351.6 million. The stablecoins frozen by Circle and Tether represent only a small fraction of that overall amount.
Which wallet was blacklisted by Circle?
Circle blacklisted the address labeled by Etherscan as Bitget Exploiter 8. Onchain data shows the blacklist action occurred at 05:00 UTC Friday.
Did Tether also ban the wallet?
Yes. Blockchain security firm MistTrack said Tether has since banned the wallet as well, preventing the USDT in that address from moving.
Why can USDT and USDC be frozen?
USDT and USDC are centralized stablecoins whose issuers can blacklist specific addresses under certain circumstances. Once an address is blacklisted, the affected tokens cannot be transferred from that wallet.
Why can the ETH not be frozen?
ETH is the native asset of Ethereum and is not controlled by a centralized issuer with a blacklist function. That means no stablecoin issuer can freeze the more than 63,000 ETH still held in other exploiter addresses.
What did Bitget say caused the hack?
Bitget CEO Gracy Chen said attackers compromised a backend system in the exchange's wallet infrastructure, spoofed transaction data and triggered the authorization process to move funds out. She ruled out a private key compromise.
Does Bitget say users are covered?
Chen said Bitget's user protection fund, which holds over $464 million, covers the loss. That statement is intended to reassure users that the exchange has resources to absorb the impact.
How does this compare with the Drift hack?
Circle's faster response contrasts with criticism after April's $285 million Drift hack, when about $232 million in stolen USDC moved from Solana to Ethereum through Circle's own transfer infrastructure before broader action was taken.
