Stablecoin Giants Freeze Hacker’s Funds
In the immediate aftermath of the $351.6 million Bitget hack, stablecoin issuers Circle and Tether moved to freeze assets linked to the exploit. Onchain data shows that Circle blacklisted a wallet labeled “Bitget Exploiter 8” by Etherscan at 05:00 UTC on Friday, targeting a specific address holding over 170 ETH, 218,023 USDT, and nearly 100,000 USDC. Tether also banned the wallet, according to MistTrack. These rapid actions resulted in approximately $318,000 in stablecoins being locked down—just a fraction of the total stolen.
Despite the high-profile intervention from Circle and Tether, MistTrack’s ongoing analysis reveals that other exploiter-controlled wallets still command more than 63,000 ETH, a sum worth tens of millions of dollars at current prices. The bulk of the stolen funds remain outside the reach of centralized issuers and law enforcement.
Circle’s freeze occurred at 05:00 UTC on Friday, targeting the “Bitget Exploiter 8” address flagged by Etherscan.
Bitget Hot Wallets Breached, Cold Safe
Bitget CEO Gracy Chen confirmed that attackers compromised a backend system in the exchange’s wallet infrastructure, spoofing transaction data to trigger unauthorized fund transfers. The breach affected several hot wallets—crypto wallets connected to the internet for operational liquidity—while cold wallets holding user funds stayed untouched. Independent blockchain researchers noted that at least three hot wallets and one cold wallet across multiple blockchains were involved in the incident, with assets such as ETH, BNB, AVAX, and USDT0 siphoned out.
Chen stated publicly that Bitget’s cold wallets and user balances remained secure throughout the event. However, withdrawals were immediately paused pending a comprehensive security review. Trading and deposits continued without interruption.
The hackers’ ability to bypass internal authorization checks highlights persistent vulnerabilities in exchange infrastructure.
See Also
User Protection Fund to the Rescue
While onchain data initially suggested around $183 million in digital assets had been moved from wallets labeled as belonging to Bitget, later assessments confirmed a total exposure of $351.6 million. This figure is significant but falls within coverage limits: Bitget maintains a User Protection Fund that CEO Gracy Chen says held over $464 million at the time of the breach. She assured customers that this reserve would fully cover losses stemming from the attack.
There is a tension between Bitget’s public insistence that “user funds are safe” and its temporary suspension of withdrawals—a move likely intended to prevent further unauthorized transactions but which left customers unable to access their assets for an unspecified period. As of September 24, 2026 at 22:10 UTC, Bitget’s native token BGB had dropped 2.9% following news of the hack; meanwhile, Bitcoin and Ether saw minor declines of 0.29% and 0.2% respectively during the same window.
The contrast between Bitget’s robust protection fund and immediate market jitters underscores how even well-capitalized exchanges can face reputational fallout after major breaches.
North Korean Hackers Suspected, CEO Says
During a live Q&A on X after Thursday’s attack, Gracy Chen revealed that preliminary investigations had traced IP addresses used in the breach to VPN services previously associated with North Korean hacking groups. Security investigators flagged similarities with earlier DPRK-linked exploits; notably, North Korean hackers were tied to an estimated $2.02 billion in crypto theft during 2025—including a $1.5 billion Bybit hack attributed by U.S. authorities to DPRK actors.
Despite these clues pointing toward North Korea’s involvement, Chen emphasized there was no evidence suggesting an inside job at Bitget itself. Onchain researcher Specter tracked portions of stolen XRP through Ethereum addresses connected to prior exploits like “AFX EXPLOITER,” reinforcing suspicions about repeat offenders using similar laundering tactics across incidents.
It remains uncertain whether law enforcement or industry efforts will recover any meaningful portion of the missing funds.
Factors to watch closely
If Bitget does not resume withdrawals following its security review, which began after the $351.6 million hack on Thursday, user access to funds will remain restricted; Circle and Tether have already frozen approximately $318,000 in stablecoins from a wallet linked to the exploit as of 05:00 UTC Friday, but over 63,000 ETH in other exploiter addresses remains unfrozen.
