Summary

  • Circle and Tether have blacklisted a wallet associated with the Bitget hack, preventing access to approximately 99,990 USDC and 218,023 USDT (around $318,000) at the contract level; Circle took action at 05:00 UTC on Friday, with Tether following suit a few hours later.
  • The wallet also contained about 170 ETH, which remains unaffected since issuers can freeze their own tokens but not Ethereum; other addresses linked to the exploiters reportedly hold over 63,000 ETH that is also untouchable.
  • This action represents a minor recovery in a breach estimated at roughly $387 million, with the Lazarus Group suspected to be behind the attack, while Bitget’s protection fund of $464 million is set to cover losses.

Circle and Tether have taken steps to freeze a wallet linked to the significant Bitget exchange hack, effectively blocking around $318,000 in stablecoins from the hacker. However, the majority of the stolen assets had already been moved out of reach before the companies could intervene.

According to blockchain records, Circle blacklisted the wallet, identified as "Bitget Exploiter 8" on Etherscan, at 05:00 UTC on Friday, utilizing the freeze function embedded in its USDC token contract.

Myriad: Where is Ethereum heading next? Make your prediction.

About seven hours later, Tether followed with a transaction on its multisig wallet that added the same address to the blacklist for USDT. Together, these actions effectively locked in around 99,990 USDC and 218,023 USDT.

While the wallet also contained approximately 170 ETH, this portion remains unaffected, highlighting a significant limitation of stablecoin freezes: issuers can blacklist their tokens at the contract level, but they cannot freeze Ethereum itself.

This limitation explains why so little was retrieved. The hacker reportedly rushed to convert assets that could be frozen into ETH before the issuers could respond, consolidating stolen tokens into new wallets and swapping stablecoins within minutes.

Blockchain tracking shows that other addresses associated with the exploiter still possess over 63,000 ETH that remains unreachable by any issuer.

The freezing actions represent only a small fraction of one of the largest exchange breaches this year. The Bitget hack drained hundreds of millions of dollars, with preliminary estimates suggesting losses of about $387 million, and analysts have indicated that North Korea’s Lazarus Group may be involved.

According to Bitget CEO Gracy Chen, attackers exploited a vulnerability in the exchange's wallet infrastructure, manipulating transaction data to execute unauthorized transfers, while confirming that there was no compromise of private keys. The exchange has announced that a user protection fund, holding more than $464 million, will be available to cover the losses incurred.

The swift blacklisting has drawn attention as a quicker response compared to previous incidents, though it has also reignited discussions regarding the centralized control that issuers maintain over assets that are ostensibly permissionless.