Circle and Tether moved quickly on Friday to blacklist a wallet that had received a portion of the funds stolen in the recent Bitget exploitation. The address, identified on-chain as the eighth exploiter, was frozen at 05:00 UTC, halting the transfer of roughly $318,000 in USDC and USDT. The action represents a marked contrast with the issuers’ handling of a previous large-scale theft earlier this year.

Scope of the frozen assets

The restricted wallet holds approximately 170 Ethereum, 218,023 USDT and 99,990 USDC. While the stablecoins are now immobile, the broader theft involved more than 63,000 Ethereum spread across multiple addresses that remain outside the reach of any stablecoin issuer. Consequently, the frozen amount constitutes only a small slice of the total $351.6 million taken from Bitjoin’s platform.

Comparison with earlier incidents

During the April incident involving a $285 million exploit of a different exchange, the same issuers faced criticism for allowing over $232 million in USDC to traverse chains before intervening. In that case, the attacker leveraged Circle’s cross-chain bridge to move funds from Solana to Ethereum. The present response demonstrates a faster, more decisive use of blacklisting tools, though the issuers note that they act only when legally mandated.

Bitget’s internal breach details

Bitget’s chief executive explained that the attackers compromised a backend component of the exchange’s wallet infrastructure. By falsifying transaction metadata, they triggered the system’s authorization flow, enabling the movement of assets without a private-key breach. The exchange’s user protection fund, which holds more than $464 million, is slated to reimburse affected clients in full.

Limitations of issuer-level freezes

Stablecoin issuers can only freeze assets that are directly under their control, such as USDC and USDT. Tokens native to other blockchains—most notably Ethereum—cannot be immobilized through the same mechanisms. This technical limitation means that while a fraction of the stolen stablecoins is now locked, the majority of the illicit proceeds remain in circulation.

Implications for future security measures

The incident underscores the growing reliance on issuer-level interventions as a line of defense against large-scale crypto thefts. It also highlights the need for broader industry standards that could address the freeze-ability of native blockchain assets, potentially through regulatory or protocol-level innovations.

Why it matters

The rapid blacklisting by Circle and Tether signals an evolving stance among stablecoin providers toward active participation in post-theft mitigation. Although the frozen funds represent a modest portion of the overall loss, the move may set a precedent for faster issuer action in future attacks, reinforcing the protective role of user-fund insurance schemes while also exposing the limits of current freeze capabilities on non-stablecoin assets.