Skip to content

Invest2 publishers3 min readPublished

Circle and Tether froze about 0.08% of the $387.5 million stolen from Bitget

Circle and Tether froze about $318,000 tied to the $387.5 million Bitget hack after the attacker had swapped most of it into Ether. Bitget's own protection fund is paying customers, so the cost lands on the exchange whose hot-wallet software was breached.

The Investor · Invest desk

Illustration accompanying Circle and Tether froze about 0.08% of the $387.5 million stolen from Bitget

What happened

  • Circle and Tether froze about 99,990 USDC and 218,023 USDT, roughly $318,000, in a wallet tagged Bitget Exploiter 8 on Etherscan.
  • Trackers say attacker-linked addresses beyond the frozen one still hold more than 63,000 ETH, an asset no stablecoin issuer can freeze.
  • Bitget raised its loss estimate from $351.6 million to $387.5 million after counting Zcash and TRON transfers, and says the rise reflects the original breach, not a new theft.
  • Bitget CEO Gracy Chen has said attackers compromised a backend wallet system and spoofed transaction data, and she ruled out a private-key compromise.
  • Bitget says its User Protection Fund, worth more than $464 million, will cover customer losses.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost If Bitget's fund pays the full loss it gives up about five-sixths of its balance, while the issuer freezes offset roughly 0.08% of the bill.
  • constraint A contract-level blacklist cannot reach Ether, so a freeze that lands hours after a theft swapped out in minutes catches only what the attacker left behind.
  • decision With issuers unable to touch the 63,000-plus ETH, Bitget's recovery now rests on other exchanges acting on its published addresses and on paying a 5% bounty for what they catch.

Set the $318,000 against the $387.5 million Bitget now puts on the breach and the freeze comes to about 0.08% of the loss, or eight cents in every hundred dollars stolen [1]. Even the correction to Bitget's own tally is far larger: the Zcash and TRON transfers left out of the first count added $35.9 million, roughly 113 times what Circle and Tether locked up [5].

Timing accounts for most of the gap. Bitget's systems flagged unauthorized transfers from its hot wallets at 18:31 UTC on September 24 [6]. Circle blacklisted the address at 05:00 UTC the next day and Tether about seven hours after that [2]. The first freeze landed roughly ten and a half hours after the alarm, and the second close to 17.5 hours in [2][3]. According to Decrypt, the attacker was swapping stablecoins out within minutes [5]. Quicker issuers would not have changed much. In the Drift Protocol case Circle took six hours to act while more than $223 million crossed its CCTP bridge, and Tether's USDT0 freeze, the fast one, still came about 90 minutes after the hack, Cryptopolitan reported [15].

Gracy Chen's account puts the failure in backend software that approves hot-wallet transfers, with no stolen key involved [8], and Bitget says its cold wallets were untouched [9]. I think the defense has to be built there. A blacklist reaches only the issuer's own token, and the roughly 170 ETH sitting in the frozen wallet itself is still spendable [3].

Tether's record is the counter-case. It says it has worked with more than 340 institutions in 65 countries to help freeze over $4.4 billion of assets [16], and Decrypt described this blacklisting as faster than some past incidents [17]. On the other side, on-chain investigator ZachXBT has alleged that Circle failed to intercept more than $420 million since 2022, Cryptopolitan reported in April [14]. Bitget listed ten affected assets, USDC and USDT among them, but did not give amounts for each [19], so the record cannot show how much of the loss was ever freezable.

Customers are being paid from Bitget's balance sheet, or rather from a protection fund held against it [10]. If that fund pays the full $387.5 million, it covers the loss about 1.2 times over and keeps at least $76.5 million, roughly a sixth of its size [4]. Account holders, whose balances Bitget says show no discrepancies, carry none of the cost [9]. So far the exchange carries all but the 0.08% [1].

Further recovery depends on the Ether [4]. Exchanges acting on the addresses Bitget published could freeze some of it at deposit, with Bitget's 5% bounty on frozen and recovered funds as the incentive [11]. Decrypt reports that analysts have named North Korea's Lazarus Group as a possible culprit [13]. Mandiant and SlowMist, both brought in by Bitget, could also describe a different entry point from the one Chen gave [12]. I'd expect the fund to absorb nearly all of the loss. A sizeable share of that Ether frozen at exchanges would prove the view wrong.

What to watch

  • Bitget's withdrawal schedule, promised by 04:00 UTC on September 26, and whether it reopens all ten affected assets at once.
  • Movement of the 63,000-plus ETH, and any exchange freezes at deposit addresses claimed under Bitget's 5% bounty.
  • Mandiant and SlowMist findings on the backend compromise Gracy Chen described, and on the possible Lazarus Group link.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories