Circle and Tether's Limited Freeze Power Exposed in Bitget Hack
On September 24, at 18:31 UTC, Bitget's systems flagged unauthorized transfers from its hot and warm wallets. The exchange's CEO Gracy Chen explained that the attacker compromised a critical backend system within their wallet infrastructure, spoofed transaction data, and triggered the authorization process to move funds out.
The loss was initially estimated at $351.6 million but later revised to $387.5 million after investigators found additional transfers of Zcash and TRON. The attackers converted freezable stablecoins into Ether (ETH) within minutes, which has no company behind it, making it impossible for anyone to freeze.
Circle blacklisted one exploiter address at 05:00 UTC on September 25, freezing 99,990 USDC. Tether followed about seven hours later, freezing 218,023 USDT at the same address. However, this only caught a mere $318,000 out of the total $387.5 million stolen.
Bitget has assured users that their balances are intact and its User Protection Fund covers the full loss. The exchange will resume withdrawals in orderly phases following the security incident. Circle's decision to freeze within 10 hours of the first stolen transfer may indicate a change in behavior after facing criticism for staying on the sidelines during the April hack.