Circle and Tether recently moved to freeze stablecoins linked to the $387.5 million Bitget hack, a response that marks a notable shift from the handling of the earlier Drift Protocol exploit and suggests the industry has become quicker to act when stolen funds enter centralized stablecoin infrastructure.
Circle blacklisted a wallet linked to the Bitget attacker at 0500 GMT, hours after the exchange detected un-authorized transfers from its hot wallets. The wallet contained about 99,990 USDC and 218,023 USDT, worth roughly $318,000, according to on-chain data.
Tether subsequently blacklisted the same address.
STABLECOINS | Leading Stablecoin Issuers Freeze Over $300K Stolen in the Latest Bitget Hack
The intervention came after BitGet identified the attack on September 24 2026 and began tracing the stolen assets. The exchange later raised its estimate of affected assets to about $387.5 million saying the higher figure reflected additional assets identified on networks including TRON and ZCash rather than further unauthorized transfers.
The response contrasts with the April 2026 Drift hack when about $230 million in stolen USDC was moved from Solana to Ethereum through Circle’s Cross-Chain Transfer Protocol. On-chain investigator, ZachXBT, criticized Circle at the time for failing to freeze the funds despite having several hours to act.
DeFi | Solana DEX Hit by the Largest DeFi Exploit of 2026 So Far
Circle then said it freezes assets when legally required.
The freezing of nearly $58 million in USDC connected to the LIBRA memecoin scam in 2025 is a example of how Circle would only comply with such directives if accompanied by a legal request. The USDC memecoin scam freeze was reportedly part of an ongoing lawsuit spearheaded by the controversial law firm, Burwick Law.
REGULATION | $USDC Stablecoin Issuer Sets a Precedent by Freezing Funds Related to a Crypto MemeCoin Scam
The latest Bitget incident therefore provides an early indication that the Drift episode may have changed expectations around how quickly stablecoin issuers should respond to major hacks.
Rather than waiting for the stolen assets to move further through the ecosystem, or for a legal and law enforcement request, Circle and Tether used their ability to blacklist their own tokens once an attacker-controlled address was identified.
The response remains limited. Most of the stolen assets are held in ether and other cryptocurrencies that stablecoin issuers cannot freeze with more than 63,000 ETH still tracked across attacker-controlled addresses.
Still, the significance is less about the roughly $318,000 frozen in this case than the speed and coordination of the response. The Drift hack exposed the consequences of allowing large amounts of stolen USDC to move across chains; the Bitget response shows stablecoin issuers acting more directly when they have the technical ability to stop funds.
For stablecoin companies, the precedent from Drift appears to be becoming clearer:
When a major hack happens, speed can determine whether issuer-controlled assets remain recoverable or disappear deeper into the crypto ecosystem.
CASE STUDY | This Stablecoin Freeze Sets a Legal Precedent for Privacy DeFi
Stay tuned to BitKE for latest stablecoin developments globally.
Join our WhatsApp channel here.
Follow us on X for the latest posts and updates
Join and interact with our Telegram community
________
