Circle used the built-in pause function in the USDC contract to blacklist a wallet identified as “Bitget Exploiter 8” at 05:00 UTC on Friday. Within the next several hours, Tether’s multisig signed a transaction that added the same address to the USDT blacklist. Together the two actions locked roughly 99,990 USDC and 218,023 USDT, amounting to about $318,000.

Why the Ethereum remained untouched

The address also contained close to 170 ETH, but neither issuer can freeze native Ethereum because it is not part of their token contracts. This technical limitation meant the attacker could preserve a substantial portion of the proceeds by converting the stablecoins into ETH before the blacklists were applied. Blockchain monitors now show more than 63,000 ETH residing in related addresses that remain out of reach for any issuer.

Context of the larger breach

The freeze represents a small portion of a breach estimated at $387 million. The hack, attributed by analysts to the Lazarus Group, involved a compromise of Bitget’s wallet infrastructure rather than a private-key leak. Bitget has pledged to cover losses from its user protection fund, which holds over $464 million.

Speed of response and ongoing debate

Circle’s action at 05:00 UTC and Tether’s follow-up several hours later were faster than in many past incidents, drawing attention to the ability of stablecoin issuers to act swiftly. At the same time, the episode reignites discussion about the centralized power that issuers wield over assets that are marketed as permissionless.

Broader implications for the ecosystem

The incident underscores the dual nature of stablecoins: they can be quickly disabled by their creators, yet the underlying blockchain assets remain fully controllable by anyone with the private key. This split creates a scenario where only a fraction of stolen value can be reclaimed, prompting calls for more comprehensive security measures and possibly regulatory scrutiny of issuer freeze powers.

Why it matters

The Bitget case illustrates both the protective potential and the inherent limits of issuer-driven freezes. While Circle and Tether were able to lock a modest amount of stablecoins, the attacker’s ability to shift value into Ethereum left the majority of the funds beyond recovery. The episode may influence future policy discussions on how much control issuers should retain and how users can safeguard assets against large-scale exploits.