Cryptocurrency Prices by Coinlib

Stablecoin Issuers Move Against Funds Linked to the Bitget Breach

Roughly $318,000 in dollar tokens reportedly blacklisted

Tether and Circle have moved to restrict stablecoins associated with the massive security incident at Bitget, demonstrating one of the clearest differences between centrally issued tokens and decentralized crypto assets.

According to multiple reports, addresses containing approximately $318,000 worth of USDT and USDC were blacklisted following the Bitget hack. The intervention prevents the affected stablecoins from being freely transferred through the tokens’ normal smart-contract infrastructure.

The amount immobilized, however, is tiny compared with the overall scale of the attack. Bitget CEO Gracy Chen said preliminary findings put the exchange’s losses at approximately $351.6 million. That gap is important: a stablecoin freeze can interrupt a hacker’s ability to move certain assets, but it does not automatically provide a recovery mechanism for an entire multi-asset theft.

The incident therefore offers a real-world test of an increasingly important security question. How much power do crypto companies actually have to stop stolen crypto funds once attackers control them?

Bitget says the incident was confined to selected wallets

Bitget has said unauthorized transfers affected a limited group of wallets and that the majority of platform assets were not impacted. The company has also stated that private keys were not compromised, pointing instead to an attack involving its wallet backend and manipulated transaction information.

That distinction could become significant as investigators reconstruct exactly how the breach occurred. A failure involving transaction processing or internal wallet infrastructure can require very different remediation from a straightforward theft of signing keys.

Why USDT and USDC Could Be Stopped While Ether Kept Moving

Centralized stablecoins contain intervention mechanisms

The response from Tether and Circle highlights an unusual feature of major fiat-backed stablecoins. Although USDT and USDC move across public blockchains, their issuers maintain administrative capabilities that can restrict addresses under certain circumstances.

This architecture makes a stablecoin freeze technically possible when an issuer identifies tokens connected to exploits, sanctions or other prohibited activity. Blacklisting does not necessarily mean the underlying dollar value has already been returned to a victim. Recovery or reissuance may involve additional technical and legal procedures.

For exchanges facing an attack, though, rapid intervention can still be valuable. Every asset that an attacker cannot readily transfer, swap or bridge reduces the immediately liquid portion of the haul.

Ether has no equivalent issuer to call

Most of the assets connected with the Bitget hack were reportedly held in ether rather than centrally controlled stablecoins. ETH cannot simply be frozen by an issuer because no company possesses an Ethereum-wide administrative switch capable of disabling ordinary ether at a specific address.

Investigators can trace ETH and exchanges can independently reject deposits associated with identified addresses. Those measures may make laundering more difficult, especially when an attacker attempts to convert assets into fiat currency.

But they cannot stop an address from making a valid Ethereum transaction.

That difference explains why blacklisting around $318,000 does not substantially neutralize a theft measured in hundreds of millions of dollars. The stablecoin freeze is meaningful for the assets affected, but most of the reported haul remains outside that particular form of centralized control.

Investigators Examine Possible North Korea Indicators

VPN and IP evidence forms part of the early investigation

The Bitget hack is also attracting attention because the exchange is investigating possible links to a North Korean hacking operation. Chen said preliminary analysis uncovered IP information corresponding with VPN selections associated with a DPRK-linked group.

Such findings should not be treated as definitive attribution on their own. Sophisticated attackers routinely use VPNs, proxies, compromised systems and intentionally misleading infrastructure. Establishing responsibility for a major cyberattack typically requires combining blockchain evidence with server records, behavioral patterns and other technical intelligence.

Still, the possibility is notable. North Korean hacking organizations have repeatedly been accused by governments and blockchain intelligence companies of targeting crypto businesses to obtain digital assets.

Onchain tracking could reveal the attackers’ next moves

Large cryptocurrency thefts can create a paradox for attackers: blockchain assets are portable, but public ledgers can also make their movement highly visible.

Investigators will likely watch for swaps, bridges, decentralized exchanges and other services that could be used to disperse the stolen crypto funds. Centralized platforms may also increase scrutiny of addresses identified as being connected to the breach.

The challenge becomes harder when assets cross multiple networks or move through protocols designed to complicate transaction tracing. Speed matters because attackers often begin fragmenting or exchanging stolen assets soon after a successful breach.

Bitget’s Protection Fund Faces a Major Real-World Test

The exchange says users will be covered

Bitget has said losses associated with the security incident will be covered through its User Protection Fund. That commitment could become just as important for customers as the technical investigation itself.

Protection funds are intended to provide an additional financial buffer when exchanges experience extraordinary events. Yet an incident approaching $352 million demonstrates why the composition, liquidity and availability of those reserves matter.

Even if the platform can make affected users whole, the Bitget hack represents a substantial test of its emergency resources and operational response.

The situation also illustrates why users should distinguish exchange-level protection mechanisms from traditional bank deposit insurance. Crypto protection funds are generally structured by individual platforms and do not necessarily carry the same legal guarantees as government-backed deposit programs.

Freezing assets is not the same as recovering losses

The involvement of Tether and Circle may sound like direct reimbursement, but the concepts are different. A stablecoin freeze restricts token movement. Reimbursement concerns who ultimately absorbs the financial loss.

This distinction becomes particularly important when only a small fraction of stolen assets consists of centrally controllable stablecoins. Even successful blacklisting leaves the exchange, investigators and other ecosystem participants with the much larger problem of tracking assets such as ETH.

For Bitget, restoring normal operations and demonstrating that unaffected reserves remain secure will be essential alongside any attempt to recover funds.

The Breach Highlights Crypto’s Split Security Architecture

Centralization can provide a security lever and a trade-off

The Tether and Circle response illustrates an enduring tension within digital assets. Issuer controls can be useful during hacks because they create an emergency mechanism that decentralized native assets intentionally lack.

That same capability introduces centralization. Holders of USDT or USDC ultimately rely on an issuer with the technical ability to restrict specific tokens under defined circumstances.

Neither architecture is universally superior. Instead, they create different risk profiles. Stablecoin users accept an element of issuer control, while holders of native assets such as ether gain stronger resistance to unilateral freezing but lose that potential recovery tool after theft.

The Bitget hack puts both sides of that trade-off on display within a single incident.

Exchanges remain responsible for defenses before assets leave

Blockchain monitoring, address blacklisting and coordinated action between companies can reduce the damage after an exploit. They are still secondary defenses.

Once attackers successfully withdraw crypto, recovery becomes uncertain. That makes prevention—wallet isolation, transaction verification, access controls, monitoring and carefully designed withdrawal infrastructure—especially important for centralized exchanges.

A $318,000 stablecoin freeze matters, but against reported losses of about $351.6 million, it also demonstrates how limited post-exploit intervention can be.

Frequently Asked Questions

How much was reportedly stolen in the Bitget hack?

Bitget CEO Gracy Chen said preliminary findings indicated losses of approximately $351.6 million. The company reported that only a limited number of wallets were affected and has said the losses will be covered through its User Protection Fund.

How much USDT and USDC was frozen after the attack?

Reports indicate that approximately $318,000 of USDT and USDC associated with the incident was blacklisted. The action involving Tether and Circle can prevent those specific stablecoins from being transferred normally, although freezing tokens does not itself mean the money has already been recovered.

Why can’t the stolen ether simply be frozen too?

Ether is Ethereum’s native asset and has no centralized issuer with authority to blacklist individual ETH balances. Exchanges can flag addresses, investigators can follow transactions, and service providers can refuse suspicious deposits, but no company can impose an issuer-level freeze on native ETH.

By Fazzio