Newsroom
25 September, 2026 / News / AI / Tags: bitget, usdc, blacklisted, circle, freeze

Stablecoin issuers blacklisted a linked wallet holding USDC and USDT, but most stolen assets had already been converted to ETH beyond their reach
Circle and Tether have blacklisted an Ethereum wallet tied to the Bitget exchange breach, immobilizing roughly $318,000 in stablecoins. The actions come after attackers drained hundreds of millions of dollars from the platform in one of the larger exchange incidents of the year.
On-chain data shows Circle blacklisted the address, labeled "Bitget Exploiter 8" on Etherscan, at 05:00 UTC on September 25. The move locked approximately 99,990 USDC using the freeze function built into the USDC token contract. Roughly seven hours later, Tether added the same address to its USDT blacklist through a multisig transaction, freezing about 218,023 USDT.
The wallet also held around 170 ETH that remained movable. Stablecoin issuers can restrict their own tokens at the contract level, but they have no authority over native Ethereum transfers.
The frozen amount represents only a fraction of the total losses. Bitget estimated the unauthorized transfers at approximately $351.6 million. Some on-chain trackers placed the figure higher, with estimates reaching roughly $387 million depending on asset prices at the time of measurement.
Blockchain monitors indicate other addresses linked to the exploit still control more than 63,000 ETH. Those holdings sit outside any stablecoin issuer’s control. Trackers reported that the attacker moved quickly to consolidate stolen tokens into new wallets and swap freezable stablecoins into ETH within minutes of the transfers.
Security researcher Taylor Monahan noted on-chain activity showing USDC moving through wallets as the attacker converted assets. The researcher questioned the timing of intervention while funds remained in USDC form.
Bitget’s security systems detected unauthorized transfers from certain hot wallets at 18:31 UTC on September 24. The exchange suspended customer withdrawals, activated emergency procedures, and stated that deposits and trading continued without interruption. Cold wallets were reported as unaffected and account balances as accurate.
Chief Executive Officer Gracy Chen said the attackers compromised a backend system within the exchange’s wallet infrastructure. They spoofed transaction data to trigger unauthorized transfers without submitting standard customer withdrawal requests. Chen ruled out any compromise of private keys.
Bitget notified law enforcement and on-chain security firms and flagged addresses connected to the abnormal activity. The company stated that its user protection fund, holding more than $464 million, would cover customer losses.
On-chain estimates of the stolen portfolio included substantial holdings of XRP, ETH, and USDC among other assets. One tracker listed roughly 102.93 million XRP valued at about $157.48 million alongside tens of thousands of ETH and more than 21 million USDC at the time of its update.
Circle has stated that it exercises freeze capabilities when legally compelled by an appropriate authority. The company’s terms reserve the right to block addresses associated with illegal activity or violations of its rules, while noting that completed on-chain USDC transactions cannot be reversed.
In an April statement following a separate incident, Circle said tools for faster intervention exist but that legal frameworks allowing quicker coordinated action while protecting legitimate holders’ rights remain incomplete. The company called for clearer rules across protocols, wallets, exchanges, and issuers.
Researchers have previously criticized response times in other cases involving suspected illicit USDC flows. One investigator compiled a list of earlier incidents totaling more than $420 million in which action was described as limited or delayed. A separate U.S. civil case related to another exploit has raised questions about the movement of stolen USDC across chains before freezes occurred.
Some analysts have pointed to North Korea’s Lazarus Group as a possible actor behind the Bitget incident based on observed patterns, though the exchange has not confirmed attribution. Bitget said it continues to investigate the entry point and plans to release a full incident report after system remediation.
The blacklisting of the Bitget-linked wallet has renewed discussion about the practical limits of stablecoin freezes when attackers convert assets rapidly into native cryptocurrencies that no issuer can restrict.









