The attack on Bitget withdrew approximately US$ 387.5 million from addresses controlled by the exchange, according to the company's latest estimate. But one of the most concrete responses to the incident reached only about US$ 318,000 in USDC and USDT. Circle and Tether blocked stablecoins held in a wallet linked to the attacker, while more than 63,000 ETH remained beyond the reach of any issuer capable of taking similar action.

The difference turns the hack into something bigger than yet another security test for an exchange. It exposes two radically different recovery architectures in crypto: one in which there is an entity with administrative power to prevent the movement of an asset and another in which, once the transaction is completed, there is no central authority capable of simply freezing it.

For exchanges and custodians, this difference is beginning to matter not only as a principle of decentralization but as an operational variable in incident response.

The freeze worked, but applied to only 0.08% of the confirmed value

Bitget detected unauthorized transfers at 18:31 UTC on September 24. The company initially estimated the incident at US$ 351.6 million, but later raised the total to approximately US$ 387.5 million, after including transfers in Zcash and TRON that were not in the initial accounting. Cold wallets remained intact, according to the exchange.

Circle added an address identified as linked to the attack to a blocklist; it held approximately 99,990 USDC. Tether did the same with about 218,023 USDT in the wallet. In total, approximately US$ 318,000 were prevented from circulating.

Compared with the US$ 387.5 million currently attributed to the incident, this represents approximately 0.08%.

Frozen stablecoins represent only a fraction of the assets still linked to the Bitget hack.
Comparison of ETH, BNB, and USDT/USDC linked to the Bitget hack, highlighting US$ 318,000 frozen.

The small number, however, does not mean the mechanism is irrelevant. It shows something else: the usefulness of freezing depends less on the size of the attack than on the composition of the stolen assets, the speed of detection, and the time needed to identify the addresses before the attacker converts the tokens.

In Bitget's case, a large part of the funds was already in ETH. CoinDesk reported that other addresses associated with the attacker held more than 63,000 ETH. Unlike USDC or USDT, ether is Ethereum's native asset and does not have an issuer with administrative powers over its balances.

Ethereum's own documentation is explicit: there is no central authority capable of freezing, confiscating, or recovering ETH from a wallet. Confirmed transactions also cannot simply be reversed by a company or by the Ethereum Foundation.

Stablecoins carry a recovery layer that ETH does not have

USDC and USDT work differently because there are companies responsible for issuing the tokens.

Circle's terms allow it to block addresses and prevent USDC transfers under certain circumstances, including activities considered illegal and orders from competent authorities.

Tether also maintains blocking mechanisms. Its terms allow it to place addresses on restrictive lists and freeze USDT, while the company adopted an additional policy in 2023 to block wallets associated with the OFAC sanctions list.

That capability is no longer exceptional. Tether says it has frozen approximately US$ 4.2 billion in assets related to illicit activities in cooperation with authorities and other market participants. In April 2026, for example, the company announced the freezing of US$ 344 million in USDT distributed across only two addresses.

This creates an unusual property for an asset that circulates on a public blockchain. The transaction remains recorded and is not erased, but the economic utility of the tokens can be interrupted by the issuer.

Stablecoins and ETH follow distinct recovery paths after an attack.
Flow compares the recovery of USDC and USDT, which can be frozen by issuers, with ETH, which depends on tracking and subsequent interception.

For hack victims, this centralization can work as an additional layer of defense after preventive controls have already failed.

But there is an important difference between freezing and recovering. Immobilizing USDT or USDC does not mean the money automatically returned to Bitget. Restitution may require additional procedures from the issuer, cooperation between companies, and, depending on the situation, legal proceedings.

The real asset in a crisis can be time

The Bitget case also shows why speed is becoming part of the security architecture.

An attacker who receives USDC or USDT has a clear incentive to convert them quickly into assets that do not carry the same administrative control. The shorter the interval between the theft, the identification of the addresses, and communication with issuers, exchanges, and bridges, the greater the potentially blockable amount.

The attack on Bybit in February 2025 offers a precedent. After the theft of approximately US$ 1.5 billion in assets, different participants managed to freeze or recover parts of the funds. Bybit itself later reported that US$ 42.89 million had been frozen by partners, while mETH Protocol managed to recover tokens valued at approximately US$ 43 million.

Tether also later announced the freezing of nearly US$ 9 million linked to the attack through the T3 Financial Crime Unit.

The pattern is relevant. Recovery does not depend only on the blockchain where the attack occurred. It depends on the control points found along the path of the money.

A native asset like ETH cannot be frozen in a wallet simply because an issuer received a request. But the attacker may still encounter barriers when trying to deposit it on a centralized exchange, use certain services, or convert it into assets that have administrative controls.

This makes onchain tracking part of a race between mobility and blocking.

Custody gains a new variable: recoverability

The operational conclusion for exchanges is not simply to replace ETH with stablecoins in hot wallets.

That would create other risks and would be incompatible with the need to maintain liquidity in the assets that clients want to deposit, trade, and withdraw. Stablecoins also introduce issuer dependency, regulatory exposure, and the possibility of being blocked by an external entity.

The incident suggests, however, that different assets should also be treated according to their recoverability after a breach, and not only according to volatility, liquidity, or commercial importance.

An operational treasury can hold assets with very different profiles.

USDC and USDT allow issuer intervention. ETH depends mainly on control of the keys, subsequent tracking, and cooperation from the services through which the asset eventually passes. Other tokens may have their own administrative functions or contracts capable of pausing transfers.

This changes the design of a response playbook.

Instead of a single routine for all stolen assets, an exchange may need to know in advance who has technical authority over each token, which issuers have emergency channels, which bridges and exchanges need to receive the addresses, and how much time there is before recovery becomes significantly more difficult.

Bitget has already put this coordination model into practice. The company launched a program offering 5% on amounts effectively frozen and 5% on amounts recovered to eligible participants who voluntarily contribute to the process. It also made available a public system for tracking the addresses involved.

The same function that recovers funds also concentrates power

There is, however, an inevitable consequence of this architecture.

The mechanism that makes it possible to prevent a hacker from moving stablecoins is the same mechanism that allows the issuer to prevent any other address from moving them when its policies or legal obligations authorize that intervention.

It is a structural characteristic, not an exceptional flaw.

For users and companies that prioritize irreversibility and censorship resistance, the absence of this power in ETH is part of the asset's value. For a custodian trying to recover hundreds of millions of dollars after an intrusion, the same characteristic eliminates one of the emergency tools available in stablecoins.

The Bitget hack does not resolve this conflict. It only makes the tradeoff measurable.

In this incident, US$ 318,000 could be immobilized because there were issuers capable of acting. Tens of thousands of ETH did not receive the same treatment precisely because that authority does not exist.

The next relevant data point will be how much of the US$ 387.5 million Bitget will actually manage to freeze or recover as the assets move through exchanges, bridges, stablecoins, and other infrastructure points.

The exchange says the vulnerability responsible for the incident has already been fixed and scheduled the gradual resumption of withdrawals starting September 28.

If recovery advances mainly when the assets pass through systems with operators capable of blocking transactions, the episode will reinforce an important shift in crypto risk management: after preventing the attack, custody architecture also needs to consider what can still be done when prevention fails.

More from Radar