[ Story · STORY ]

Bitget freeze catches $318K, hack moved more

Circle and Tether froze $318K tied to the Bitget hack. The attacker had already swapped the rest into ETH first.

STORY·September 25, 2026·3 min read·By Gintautas Nekrosius
A cream field with a red net closing over a small cluster of coins while a larger shape slips through the mesh above
Issuer blacklists caught a fraction of the Bitget exploit funds.

Circle and Tether blacklisted a wallet labeled "Bitget Exploiter 8" this week, freezing roughly $318,000 in USDC and USDT tied to the exchange's hack. The attacker had already converted most of the stolen funds into ETH before either issuer could act.

The freeze mechanism

Stablecoin issuers can blacklist addresses because USDC and USDT run on permissioned smart contracts. Circle and Tether both maintain that control as a compliance backstop.

The tool works only while funds sit in USDC or USDT. Once converted to a base asset like ETH, the issuers have no lever left to pull.

What the numbers show

The freeze looks fast on paper. The math tells a different story once you compare what got locked against what the attacker actually held.

  • Roughly $318,000 in USDC and USDT frozen across the flagged wallet, per Decrypt.
  • The wallet is tagged "Bitget Exploiter 8," suggesting at least eight related addresses tied to the same exploit.
  • Most of the stolen funds had already moved into ETH before the blacklist landed, per the same report.
  • Two issuers, Circle and Tether, both acted on the same address within the same response window.

The freeze as theater

The obvious read is that Circle and Tether moved fast and shut the attacker down. The dollar figure argues against that framing.

A hacker who clears an exchange typically nets millions. $318,000 frozen against a haul that size is a rounding error, not a recovery.

The freeze works on the least sophisticated attackers, the ones slow enough to leave funds sitting in USDC or USDT. Anyone who has done this before converts to ETH within minutes, because ETH has no issuer and no blacklist function.

Bitget's hacker cleared that bar. The eight-plus tagged wallets point to a coordinated cash-out, not a smash-and-grab, and coordinated actors know which asset gives them a clean exit.

Issuer freezes protect the stablecoin's reputation more than they protect stolen value. Circle and Tether get to say they acted. The exchange and its users absorb the loss anyway, because the money that mattered was gone before the freeze order existed.

What confirms or kills this

The next few weeks will show whether this freeze recovers anything real or just closes a small side pocket of the theft.

  • Whether Bitget discloses the total exploit size; a freeze recovering under 5% of the total would confirm the theater read.
  • Whether the ETH the attacker holds moves through a mixer or bridge before any exchange can flag it.
  • Whether Circle or Tether extends blacklisting to any downstream wallets that received swapped ETH once it re-enters a stablecoin.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy