Bitget freeze catches $318K, hack moved more
Circle and Tether froze $318K tied to the Bitget hack. The attacker had already swapped the rest into ETH first.

Circle and Tether blacklisted a wallet labeled "Bitget Exploiter 8" this week, freezing roughly $318,000 in USDC and USDT tied to the exchange's hack. The attacker had already converted most of the stolen funds into ETH before either issuer could act.
The freeze mechanism
Stablecoin issuers can blacklist addresses because USDC and USDT run on permissioned smart contracts. Circle and Tether both maintain that control as a compliance backstop.
The tool works only while funds sit in USDC or USDT. Once converted to a base asset like ETH, the issuers have no lever left to pull.
What the numbers show
The freeze looks fast on paper. The math tells a different story once you compare what got locked against what the attacker actually held.
- Roughly $318,000 in USDC and USDT frozen across the flagged wallet, per Decrypt.
- The wallet is tagged "Bitget Exploiter 8," suggesting at least eight related addresses tied to the same exploit.
- Most of the stolen funds had already moved into ETH before the blacklist landed, per the same report.
- Two issuers, Circle and Tether, both acted on the same address within the same response window.
The freeze as theater
The obvious read is that Circle and Tether moved fast and shut the attacker down. The dollar figure argues against that framing.
A hacker who clears an exchange typically nets millions. $318,000 frozen against a haul that size is a rounding error, not a recovery.
The freeze works on the least sophisticated attackers, the ones slow enough to leave funds sitting in USDC or USDT. Anyone who has done this before converts to ETH within minutes, because ETH has no issuer and no blacklist function.
Bitget's hacker cleared that bar. The eight-plus tagged wallets point to a coordinated cash-out, not a smash-and-grab, and coordinated actors know which asset gives them a clean exit.
Issuer freezes protect the stablecoin's reputation more than they protect stolen value. Circle and Tether get to say they acted. The exchange and its users absorb the loss anyway, because the money that mattered was gone before the freeze order existed.
What confirms or kills this
The next few weeks will show whether this freeze recovers anything real or just closes a small side pocket of the theft.
- Whether Bitget discloses the total exploit size; a freeze recovering under 5% of the total would confirm the theater read.
- Whether the ETH the attacker holds moves through a mixer or bridge before any exchange can flag it.
- Whether Circle or Tether extends blacklisting to any downstream wallets that received swapped ETH once it re-enters a stablecoin.
