Bitget Says $351M Unauthorized Transfer Hit Hot Wallets as USDC Freeze Debate Reignites

Daily Feed
Bitget Says $351M Unauthorized Transfer Hit Hot Wallets as USDC Freeze Debate Reignites

Bitget says it caught a major unauthorized transfer, and on-chain watchers say part of the stolen USDC was quickly swapped into ETH. That’s the kind of move that turns a theft into a recovery headache and puts Circle’s USDC freeze powers back under the microscope.

Bitget said the incident hit only part of its hot and warm wallet layers, not its cold wallets. That difference matters. Hot wallets are connected to the internet and used for day-to-day operations, which also makes them an easy target. Cold wallets are offline, slower to use, and much harder for attackers to reach remotely.

The exchange said deposits and trading stayed open while withdrawals were paused. It also said account balances were accurate and that user assets remained protected. Bitget CEO Gracy Chen said the preliminary investigation ruled out a leak of wallet private keys and pointed instead to a direct intrusion into the exchange’s systems.

On-chain researcher Taylor Monahan flagged the attacker’s activity on X, while Lookonchain estimated the stolen portfolio at roughly $356.8 million. Its breakdown included 102.93 million XRP worth about $157.48 million, 31, 890 ETH worth about $85.75 million, and 21.05 million USDC.

Those numbers are estimates, not final forensic totals. Bitget’s own figure was about $351.6 million, so the gap is not huge, but it is a reminder that early incident math is usually messy. In crypto, even the spreadsheet needs a wallet.

Bitget said it identified the addresses linked to the abnormal transfers and notified law enforcement and on-chain security firms. The exchange said it would release a more detailed report later. For now, the main takeaway is simple: this was not a minor wallet slip. It was a serious breach involving a large pile of assets and a fast-moving attacker.

The part that has the crypto security crowd grinding its teeth is the USDC angle. USDC is issued by Circle, which means Circle can blocklist certain addresses and prevent them from sending or receiving the token in some cases. That is very different from bitcoin, and also different from ether, which does not have a central issuer sitting at the controls.

That power cuts both ways. If a thief is caught early enough, a stablecoin issuer can sometimes stop the stolen tokens from moving further. But if the attacker converts USDC into ETH first, freezing the original USDC address does not reach the ether that replaced it. The thief has already changed the coat before security got to the door.

Circle’s setup is one reason institutions like stablecoins. It gives them a fraud-response layer that pure bearer assets do not have. It is also one reason decentralization purists distrust them. A token that can be blocked by an issuer is useful, but it is not censorship-resistant money in the Bitcoin sense. That tradeoff is the whole argument, and it is not going away.

Circle has said in its public materials that it can block transfers to and from certain addresses under its policies, and that once a USDC transaction is initiated, it cannot be reversed or recalled. That is the hard part of the crypto reality check: the blockchain records the move, but it does not politely unwind it for you later.

So the race is not just between attacker and exchange. It is between attacker, exchange, issuer, and whatever legal process is needed to justify action. If the attacker can move from USDC into ETH before that chain finishes, the freeze window is basically gone.

That timing problem is exactly what critics keep hammering Circle about. Security researcher ZachXBT said in April that Circle had taken “minimal action or failed to act quickly enough” in 15 cases involving more than $420 million in suspected illicit USDC flows since 2022. Among the examples he cited were about $9 million in USDC tied to the July 2025 GMX hack, wallets involved in the Cetus hack that were reportedly blocked only after stolen USDC had already been converted into ETH, and a Drift case in which he said attackers moved roughly $232 million over about six hours and more than 100 transactions before converting the funds.

Those are allegations, not courtroom findings. They do, though, underline the core complaint: a freeze that arrives after the money has already been swapped, bridged, or laundered is a lot less impressive than the marketing makes it sound. On-chain visibility is useful, but seeing the thief run away is not the same thing as catching him.

The legal side of this debate is getting louder too. In April, a claimant filed a civil lawsuit in a U.S. federal district court in Massachusetts against Circle over approximately $230 million in stolen USDC routed through its Cross-Chain Transfer Protocol. The complaint also referenced Circle freezing 16 USDC-linked wallets tied to a separate sealed civil matter.

That does not prove wrongdoing by Circle. It does show that victims are increasingly willing to drag token issuers into the mess when frozen-fund timing becomes part of the recovery fight. Once stablecoins sit at the center of criminal flows, the legal questions arrive right behind them.

For Bitget users, the immediate question is practical, not philosophical: how much can the exchange recover, and how much was moved out of reach before anyone could stop it? Bitget said its cold wallets were secure, which is the good news. If the offline reserves held, the exchange may be dealing with a painful but contained operational breach rather than a full collapse of reserves.

The broader lesson is less comforting. Stablecoins are meant to be efficient digital dollars, but they are not neutral bearer assets in the pure bitcoin sense. They carry an issuer, a policy stack, and a legal process. That can help when funds are stolen. It can also mean the response is too slow for the speed of a real exploit.

Crypto keeps selling itself on immediacy, but security and recovery are still trapped in old-world timing. The chain is fast. The paperwork is not. And attackers know exactly which one usually loses the race.

Key questions and takeaways

  • What happened at Bitget?
    Bitget said it detected unauthorized transfers at 18:31 UTC on Sep. 24 and temporarily suspended withdrawals while it investigated.
  • How much was affected?
    Bitget estimated the loss at about $351.6 million, while Lookonchain estimated roughly $356.8 million based on on-chain tracing.
  • Were customer funds completely lost?
    Bitget said its cold wallets were secure and that account balances were accurate, which suggests the breach hit operational wallets rather than offline reserves.
  • Why does USDC matter here?
    Circle can blocklist certain USDC addresses, so stolen funds may be stoppable if the issuer acts before the attacker moves them elsewhere.
  • Why is swapping USDC into ETH such a problem?
    Once the USDC is converted into ETH, freezing the original USDC address no longer reaches the ether that replaced it.
  • Is Circle’s freeze power a good thing?
    Yes and no. It can help disrupt theft and illicit flows, but it also adds a centralized control point that clashes with crypto’s censorship-resistant ethos.
  • Are the criticisms of Circle proven?
    Not all of them. ZachXBT’s claims are allegations, but they reflect a real concern: freeze tools are only useful if they move faster than the attacker.
  • What should users take from this?
    Custody choices matter. Once stolen funds leave the original token form, recovery gets much harder, and nobody gets a magic undo button.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog