Stablecoin giants Circle and Tether stepped in to freeze a wallet tied to the Bitget hack, and the total they caught was about $318,000 out of $387.5 million. Bitget is one of the world’s largest crypto exchanges, and this is the biggest crypto theft of 2026 so far, so how the industry responds sets the template for the next one. Here’s why the freeze barely dented the loss, what changed in Circle’s behavior, and why that freeze power matters for anyone holding stablecoins.
What Happened at Bitget, in 60 Seconds
At 18:31 UTC on September 24, Bitget’s systems flagged unauthorized transfers from its hot and warm wallets. A hot wallet is an exchange wallet that stays connected to the internet so it can process withdrawals quickly. A cold wallet stays offline and is much harder to reach.
Bitget CEO Gracy Chen explained on X that the attacker “compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” She said private keys weren’t stolen and cold wallets stayed safe.
Here is what we can confirm at this stage:
On the attack:
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization… https://t.co/5nINjwbXpC— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
In other words, the hackers didn’t break the vault. They forged the paperwork, and the vault opened on its own.
The loss was first put at $351.6 million, then revised to $387.5 million after investigators found Zcash and TRON transfers from the same incident. The biggest pieces:
| Asset | Amount stolen | Can the issuer freeze it? |
| XRP | 102.93M XRP (~$157.5M) | No |
| Ether (ETH) | 31,890 ETH (~$85.8M) | No |
| USDT (Tether) | ~$34.75M | Yes |
| USDC (Circle) | ~$21.05M | Yes |
| USDT0 (Tether’s cross-chain USDT) | ~$19.67M | Yes, in principle |
| Others | BNB, AVAX, TRX, ZEC, 3,000 XAUt gold tokens | Mostly no (XAUt is Tether-issued) |
Chen said IP addresses matched “the VPN choices by a certain DPRK group,” pointing toward North Korea, though attribution isn’t confirmed yet.
The Freeze, by the Numbers
A stablecoin is a crypto token designed to stay worth $1, backed by cash and bonds held by a company. Because a company issues them, that company can blacklist a wallet address, which stops the tokens there from moving.
That’s exactly what happened. Circle blacklisted one exploiter address at 05:00 UTC on September 25, freezing 99,990 USDC. Tether followed about seven hours later, freezing 218,023 USDT at the same address.

Here’s our math on how much that really caught:
- About 0.08% of the total $387.5 million stolen.
- About 0.4% of the roughly $75.5 million in dollar stablecoins taken (USDT, USDC, and USDT0 combined).
The reason is simple. The attackers converted freezable stablecoins into ETH within minutes. ETH has no company behind it, so no one can press a freeze button. The same wallet Circle and Tether froze also held 170 ETH, which stayed untouched. Other hacker addresses now hold more than 63,000 ETH that no issuer can reach.
That’s the core weakness of freezing as a defense: it only works on assets that stay put, and professional hackers know that.
Circle Moved Faster This Time, and That’s the Real Shift
Here’s the part most coverage skips. In April, hackers linked to North Korea drained about $285 million from Drift Protocol and moved roughly $230 million in USDC across blockchains over several hours. Circle didn’t freeze it, and faced heavy criticism for staying on the sidelines.
At the time, Circle said its ability to freeze funds is “a compliance obligation, exercised only when we are legally compelled by an appropriate authority, through lawful process.” A class action lawsuit, McCollum v. Circle, later argued the company had a duty to act.
This time, Circle froze within about 10 and a half hours of the first stolen transfer. It hasn’t publicly said what triggered the freeze, whether a law enforcement request or its own call. Either way, our read is that the April backlash changed the math inside Circle. Moving slowly now carries a reputational and legal cost that it didn’t seem to fully price in before.
Tether, usually the faster of the two, came second here. That doesn’t change much in this case, but it shows neither company has a real-time playbook.
The Part Nobody’s Telling You: That Button Works on Your Wallet Too
The freeze power that stopped $318,000 in stolen funds is the same power that can lock tokens at any address. And freezes happen at the address level, not the transaction level.
Tether’s blacklist covered about 9,597 addresses holding $5.69 billion as of July 2026. Among addresses frozen in 2025, only 3.6% were later unfrozen, and those took a median of 18.2 days. Worse, frozen addresses can still receive new USDT, which then gets stuck too.
For everyday users, this creates a few practical risks:
- Tainted payments: If someone pays you with stablecoins traced to a hack or scam, your address could get flagged.
- Peer-to-peer trades: Buying USDT from strangers is the most common way innocent users end up holding flagged funds.
- Sanctions sweeps: Large coordinated freezes, like Tether’s Iran-linked actions this year, catch every address in the net.
None of this means stablecoins are unsafe to hold. It means they behave more like a bank balance than cash. They’re programmable, trackable, and freezable. If you want crypto that no company can freeze, that’s what assets like Bitcoin and ETH are for, with the trade-off that stolen funds can’t be frozen either.
What Bitget Users Should Know Right Now
Bitget says user balances are intact and its User Protection Fund, worth over $464 million, covers the full loss. If it covers the entire $387.5 million, that leaves a cushion of about $76.5 million, much thinner than before the hack.
Bitget will begin resuming withdrawals in orderly phases following the security incident identified on September 24.
The vulnerability involved in the incident has been identified and remediated.
Bitget’s security and technical teams have since been conducting additional… https://t.co/VZu59GnLAN
— Bitget (@bitget) September 26, 2026
Withdrawals were paused, with trading and deposits still open. Bitget committed to publishing a withdrawal restart plan by 04:00 UTC on September 26, while saying it “will not commit to a window we cannot guarantee” on the full restart. The exchange also launched a 5% bounty for anyone who helps freeze or recover stolen funds, and Bybit CEO Ben Zhou offered his team’s help tracing the money. Bitget’s own BGB token fell about 3.3% to around $1.97 after the news.
2026 Keeps Breaking Records
This hack fits a clear pattern. Two North Korea-linked attacks, Drift and the $292 million KelpDAO bridge exploit, made up 76% of all crypto hack losses through April. Bitget now tops them both, and it follows the $320 million Liquid Network drain earlier this month.
The laundering playbook is familiar, too. After KelpDAO, hackers swapped about $175 million in ETH into Bitcoin through THORChain, a cross-chain swap protocol that doesn’t require identity checks. If Bitget’s stolen ETH starts moving the same way, recovery chances drop sharply.
What we’re watching next:
- Whether Bitget’s withdrawal plan holds its timeline
- Whether Circle explains what triggered its faster freeze
- Where the 63,000+ ETH goes, and how fast
- Whether US lawmakers revisit freeze rules after the Crypto Clarity Act died in the Senate
Our take: the Bitget hack shows stablecoin freezes are a useful last line of defense, not a safety net. The real protection still has to happen before the money leaves the building.
FAQs
Is it safer to keep crypto on an exchange or in your own wallet?
Each has risks. Exchanges can be hacked or pause withdrawals, while self-custody puts all responsibility on you, including backups. Many long-term holders move savings to a hardware wallet for offline crypto storage and keep only trading money on exchanges.
How do you check whether a USDT address is frozen?
You can check freeze status by reading the USDT contract on Etherscan or Tronscan, or by using free blacklist checker tools. Do it before accepting large stablecoin payments from someone you don’t know, especially in peer-to-peer trades.
Why is XRP so often a big part of exchange hacks?
Exchanges hold large XRP balances because many customers trade it, so hot wallets carry a lot of it. In Bitget’s case, XRP made up about $157.5 million of the loss. Activity on the network is also shifting toward bigger players, as seen in how the XRP Ledger is losing users while moving billions.
What’s the difference between a hack and a wallet drainer scam?
A hack breaks into a company’s systems, like Bitget’s backend. A drainer scam tricks you into signing a transaction that empties your own wallet, often disguised as a small “test transaction,” as in the wallet drainer scam Ukraine police busted. You can’t prevent the first, but you can avoid the second.
Could AI make crypto hacks worse?
Possibly. AI tools can help attackers find bugs and write convincing phishing messages faster, but defenders use them too. Some builders are already reshaping how they hold crypto because of it, as shown when Vitalik Buterin explained his 90% crypto bet against AI hackers.
Click Here For The Original Source.
