XRP Stolen in Bitget Hack Highlights Lack of Freeze Controls
The hacker behind the Bitget exchange breach has moved approximately $83 million worth of stolen XRP from three holding wallets. This highlights a key difference between XRP, the native asset of the XRP Ledger, and issuer-controlled stablecoins such as USDC and USDT.
About 54 million XRP has left the five wallets that initially received nearly 103 million XRP stolen from Bitget. Roughly $75 million worth of XRP remains across the original accounts as of this writing.
Unlike USDC and USDT, XRP cannot be frozen by its issuer or by Ripple due to a lack of built-in freeze controls specific to XRP itself. This means that Ripple has no mechanism to block the attacker from transferring or spending the stolen XRP.
The contrast was evident in the same Bitget breach, where Circle and Tether, the issuers of USDC and USDT, froze about $320,000 in stablecoins linked to the attack using controls that allow them to blacklist addresses. Exchanges receiving the stolen XRP can also restrict accounts and prevent withdrawals, but cannot freeze the XRP while it remains in an attacker-controlled wallet.