Key points

  • Circle and Tether blacklisted stablecoins in a wallet labeled by Etherscan as Bitget Exploiter 8.
  • The address held approximately 99,990 USDC and 218,023 USDT, leaving about $318,000 frozen.
  • Bitget raised its estimate of assets transferred to attacker-controlled addresses to approximately $387.5 million after adding Zcash and Tron assets.

Circle and Tether have frozen about $318,000 in stablecoins held by a wallet linked to the Bitget security breach, according to onchain data and independent reporting published on September 25. The action immobilized a small share of the assets traced from the exchange while highlighting the different recovery options available for issuer-controlled tokens and assets such as ether.

One wallet held USDC, USDT and ether

CoinDesk reported that Circle blacklisted the address, labeled "Bitget Exploiter 8" by Etherscan, at 05:00 UTC on Friday. At the time reviewed, the wallet held about 99,990 USDC, 218,023 USDT and 170.47 ETH. Blockchain security service MistTrack said Tether subsequently banned the same address. The two stablecoin balances account for the roughly $318,000 frozen total.

Related reporting: Hyperliquid opens borrowing against HYPE and Bitcoin

Most traced assets remain outside stablecoin controls

The freeze does not recover the broader loss. CoinDesk said MistTrack's tracker showed other exploiter addresses holding more than 63,000 ETH. Unlike USDC and USDT, ether has no centralized issuer able to blacklist an address at the token-contract level. The distinction means stablecoin issuers can sometimes stop specific balances, while native blockchain assets may continue moving unless an exchange, bridge or other intermediary intervenes.

Blacklisting stops transfers, not ownership disputes

A blacklist action prevents the affected stablecoin balance from being transferred through the token contract, but it does not by itself determine who legally owns the funds or authorize their return. Any later recovery can require cooperation among the issuer, investigators, exchanges and the affected company, depending on the legal process and where the assets sit. The frozen amount should therefore be treated as immobilized, not yet recovered.

Bitget revises the incident estimate

In its latest official update, Bitget said assets worth approximately $387.5 million had been transferred to attacker-controlled addresses. That figure supersedes its initial estimate of $351.6 million and includes Zcash and Tron assets that were not part of the first accounting. Bitget said the revision reflected more complete classification of transfers rather than additional unauthorized withdrawals. The exchange also said the underlying vulnerability had been identified and remediated.

Exchange launches recovery bounty

Bitget said some affected assets had already been frozen through coordination with industry partners and launched a recovery bounty program. Under the published terms, an eligible voluntary action that directly results in funds being frozen or recovered may receive a bounty equal to 5% of the affected amount. Court orders, law-enforcement requests and other legal processes are excluded. Eligibility remains subject to Bitget's determination, so the program is not a guaranteed payment mechanism.

Tracing continues across several networks

The exchange identified primary attacker-controlled addresses on Ethereum-compatible networks, XRP Ledger, Zcash and Tron, and opened a live tracing dashboard and reporting portal for security teams and infrastructure providers. Bitget said Mandiant and SlowMist were assisting the investigation. Its update listed ETH, XRP, USDT, USDC, ZEC, USDT0, XAUt, BNB, AVAX and TRX among the affected assets.

What the freeze establishes

The confirmed development is narrow: two stablecoin issuers restricted balances in one traced wallet. It does not establish that the frozen tokens have been returned to Bitget or that the remaining assets are recoverable. The next verifiable milestones will be any transfer of frozen funds under a legal or negotiated process, restoration of withdrawals after Bitget's security checks, and a final incident report explaining the attack path and controls added to prevent a recurrence.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.