Circle and Tether freeze Bitget hacker wallets, and the recovery work enters an on-chain cooperation phase
New developments have emerged in the Bitget hacker incident. Circle and Tether have already frozen wallets associated with the attacker, totaling approximately $318,000 worth of USDC and USDT. Circle first added the relevant addresses to the blacklist, and then Tether also took corresponding measures.
However, note that this $318,000 is only a small portion compared with the scale of the billions of dollars in assets stolen in this incident. Currently, on-chain tracking shows that the attacker-related addresses still hold more than 63,000 ETH, and a large amount of the stolen assets has been converted into native assets that cannot be directly frozen by a single issuer.
The biggest significance of this for the market is not really how much money was frozen, but that once hackers’ funds enter the stablecoin ecosystem, the issuers are able to rapidly block the flow of funds. Although USDC and USDT run on public blockchains, the issuers can still freeze the relevant tokens through contract-level blacklist mechanisms.
This will directly change the path hackers take to handle stolen assets. In the past, after hackers obtained stablecoins, they could quickly transfer them via exchanges, cross-chain bridges, and DEXs. Now, once the relevant addresses are marked by security entities, core infrastructure such as Circle, Tether, and exchanges may simultaneously implement restrictions, forcing hackers to convert stablecoins into native assets like ETH and BTC faster.
In practice, on-chain tracking shows that some of the stolen stablecoins, after entering the attackers’ wallets, were quickly exchanged for ETH. This also indicates that hackers are already actively avoiding the risk of stablecoin freezing.
For the market, there is an important shift here: although crypto assets circulate on-chain, different assets have different degrees of “freezability.” USDT and USDC are subject to issuer control, while native assets like ETH and XRP do not have a centralized issuer that can directly freeze assets across the entire network.
So the key to tracking down the stolen funds next becomes: where do the funds flow, and whether they can enter exchanges, the stablecoin ecosystem, or other infrastructure that has freezing authority.
If, going forward, Circle, Tether, exchanges, and security companies continue to freeze or recover more assets, the market’s risk pricing for this hacking incident may gradually decrease. Conversely, if the attacker keeps transferring large amounts of assets like ETH and XRP and disperses them through cross-chain routes, DEXs, and so on, the difficulty of recovering the funds will increase significantly.
Therefore, the most important takeaway from this event for the crypto market is not that “stablecoins can be frozen,” but that exchanges, security entities, and stablecoin issuers are forming a cooperative on-chain mechanism for recovering stolen funds.
In the short term, the frozen amount is not enough to change the overall losses of an event on the scale of more than $300 million. In the mid term, if this cooperative mechanism can continue to recover large amounts of assets, it may instead increase market confidence in on-chain fund tracking and risk control capabilities.