Invest2 publishers3 min readPublished
Circle and Tether froze about 0.08% of the $387.5 million stolen from Bitget
Circle and Tether froze about $318,000 tied to the $387.5 million Bitget hack after the attacker had swapped most of it into Ether. Bitget's own protection fund is paying customers, so the cost lands on the exchange whose hot-wallet software was breached.
The Investor · Invest desk

What happened
- Circle and Tether froze about 99,990 USDC and 218,023 USDT, roughly $318,000, in a wallet tagged Bitget Exploiter 8 on Etherscan.
- Trackers say attacker-linked addresses beyond the frozen one still hold more than 63,000 ETH, an asset no stablecoin issuer can freeze.
- Bitget raised its loss estimate from $351.6 million to $387.5 million after counting Zcash and TRON transfers, and says the rise reflects the original breach, not a new theft.
- Bitget CEO Gracy Chen has said attackers compromised a backend wallet system and spoofed transaction data, and she ruled out a private-key compromise.
- Bitget says its User Protection Fund, worth more than $464 million, will cover customer losses.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost If Bitget's fund pays the full loss it gives up about five-sixths of its balance, while the issuer freezes offset roughly 0.08% of the bill.
- constraint A contract-level blacklist cannot reach Ether, so a freeze that lands hours after a theft swapped out in minutes catches only what the attacker left behind.
- decision With issuers unable to touch the 63,000-plus ETH, Bitget's recovery now rests on other exchanges acting on its published addresses and on paying a 5% bounty for what they catch.
Set the $318,000 against the $387.5 million Bitget now puts on the breach and the freeze comes to about 0.08% of the loss, or eight cents in every hundred dollars stolen [1]. Even the correction to Bitget's own tally is far larger: the Zcash and TRON transfers left out of the first count added $35.9 million, roughly 113 times what Circle and Tether locked up [5].
Timing accounts for most of the gap. Bitget's systems flagged unauthorized transfers from its hot wallets at 18:31 UTC on September 24 [6]. Circle blacklisted the address at 05:00 UTC the next day and Tether about seven hours after that [2]. The first freeze landed roughly ten and a half hours after the alarm, and the second close to 17.5 hours in [2][3]. According to Decrypt, the attacker was swapping stablecoins out within minutes [5]. Quicker issuers would not have changed much. In the Drift Protocol case Circle took six hours to act while more than $223 million crossed its CCTP bridge, and Tether's USDT0 freeze, the fast one, still came about 90 minutes after the hack, Cryptopolitan reported [15].
Gracy Chen's account puts the failure in backend software that approves hot-wallet transfers, with no stolen key involved [8], and Bitget says its cold wallets were untouched [9]. I think the defense has to be built there. A blacklist reaches only the issuer's own token, and the roughly 170 ETH sitting in the frozen wallet itself is still spendable [3].
Tether's record is the counter-case. It says it has worked with more than 340 institutions in 65 countries to help freeze over $4.4 billion of assets [16], and Decrypt described this blacklisting as faster than some past incidents [17]. On the other side, on-chain investigator ZachXBT has alleged that Circle failed to intercept more than $420 million since 2022, Cryptopolitan reported in April [14]. Bitget listed ten affected assets, USDC and USDT among them, but did not give amounts for each [19], so the record cannot show how much of the loss was ever freezable.
Customers are being paid from Bitget's balance sheet, or rather from a protection fund held against it [10]. If that fund pays the full $387.5 million, it covers the loss about 1.2 times over and keeps at least $76.5 million, roughly a sixth of its size [4]. Account holders, whose balances Bitget says show no discrepancies, carry none of the cost [9]. So far the exchange carries all but the 0.08% [1].
Further recovery depends on the Ether [4]. Exchanges acting on the addresses Bitget published could freeze some of it at deposit, with Bitget's 5% bounty on frozen and recovered funds as the incentive [11]. Decrypt reports that analysts have named North Korea's Lazarus Group as a possible culprit [13]. Mandiant and SlowMist, both brought in by Bitget, could also describe a different entry point from the one Chen gave [12]. I'd expect the fund to absorb nearly all of the loss. A sizeable share of that Ether frozen at exchanges would prove the view wrong.
What to watch
- Bitget's withdrawal schedule, promised by 04:00 UTC on September 26, and whether it reopens all ten affected assets at once.
- Movement of the 63,000-plus ETH, and any exchange freezes at deposit addresses claimed under Bitget's 5% bounty.
- Mandiant and SlowMist findings on the backend compromise Gracy Chen described, and on the possible Lazarus Group link.