Constatum
News

Bitget Hack: Why Only $318K of $387M Got Frozen

Constatum Team5 min read
A dark bronze deposit slot with its steel shutter closing on the last coin while the slot behind it stands empty

At 18:31 UTC on Thursday, September 24, Bitget noticed money leaving its hot wallets that nobody at Bitget had sent. By the time withdrawals were paused, about $352 million had gone out across seven chains. A few days later the figure was revised to $387.5 million, once investigators found Zcash and TRON losses too.

Part of the haul was USDT and USDC. Those are the two big tokens in crypto that somebody can switch off. Circle can freeze any USDC address. Tether can freeze any USDT address. So how much of the $387.5 million did they freeze?

About $318,000. Roughly 0.08 percent.

That number tells you a lot about how stablecoin freezes really work, and about who ends up carrying the risk. It usually isn't the hacker.

What happened

Bitget's CEO, Gracy Chen, says the attackers got into a backend system connected to the exchange's wallet infrastructure and spoofed transaction data. The approval process then signed transfers it should never have signed. No private keys were stolen and the cold wallets weren't touched. Bitget says its protection fund, about $464 million, covers the whole loss, and it has offered a 5 percent bounty on anything recovered.

Chen called North Korean involvement "very likely," pointing to IP addresses linked to VPN services used by the Lazarus Group. TRM Labs found overlaps with earlier North Korean thefts, Bybit among them, but hasn't formally attributed the attack yet. Elliptic counts Bitget as the largest theft of 2026 and the one that pushed suspected North Korean thefts for the year past $1 billion. The previous biggest was Drift Protocol, $286 million, on April 2.

Why the freeze caught so little

The attackers didn't sit on the stablecoins. They swapped most of the USDT and USDC into ETH within minutes, and ETH has no issuer and no freeze function. Some of it went across bridges straight away. One trail that investigators followed runs from USDT, bridged to Ethereum through USDT0, into about 145 ETH, and then through THORChain into roughly 4.59 BTC.

Circle blacklisted one address, labelled "Bitget Exploiter 8" on Etherscan, at 05:00 UTC on Friday. That was about ten and a half hours after the breach started. Tether added the same address to its USDT blacklist around seven hours later. Between them they locked 99,990 USDC and 218,023 USDT.

The same wallet also held about 170 ETH. It stayed where it was, untouched, because nobody can freeze it. According to MistTrack, other exploiter addresses were still holding more than 63,000 ETH.

Bitget then asked THORChain, the cross-chain swap protocol, to refuse service to the attacker's addresses. Chen said "the industry is watching" and asked it not to hide behind protocol neutrality. THORChain said no. Its design is permissionless and it doesn't block transactions. It's the same route that carried roughly $1.2 billion of the Bybit money in 2025. Within days, AMLBot had traced about 4 BTC from the Bitget theft into a Wasabi CoinJoin round.

So the freeze button exists, somebody pressed it, and it caught the leftovers.

Who a freeze actually lands on

Most people read a story like this and think of freezes as a tool for catching hackers. Look at who they work against in practice.

A professional crew knows USDT and USDC can be frozen, so they convert out fast. They don't hold stablecoins for ten hours. The people who hold stablecoins for ten hours, or ten weeks, are everyone else. The freelancer waiting to cash out an invoice. The small shop that keeps its float in USDT. The P2P seller who took a payment last Tuesday.

And issuers don't only freeze hacker wallets. They act on law-enforcement requests, on sanctions listings and on their own investigations. On September 8, Tether froze about $39 million in wallets linked to the Xinbi escrow network. A freeze is an address-level switch. It doesn't ask how the tokens got there or whether the current holder did anything wrong. If you're holding USDT at an address that gets pulled into a case, you wait, you explain, and you may never see the money again.

There's a second risk, and it's slower. Those 63,000 ETH aren't going to stay parked. Stolen funds come out over months, in small pieces, through swaps, OTC desks and P2P sellers, until they reach people who have never heard of the Bitget hack. TRM's advice to exchanges after this attack was to screen deposits "several hops downstream" of the exploiter addresses.

Read that from the other side. Exchanges won't only look at who sent you coins. They'll look at who sent your sender coins, and who sent them coins. If the client who paid you last month was funded two hops away from a Bitget-tagged cluster, your deposit is the one that gets held. Bitget's users are covered by its fund. You aren't.

Check before the money arrives

The one habit that helps is checking the wallet before you accept a payment, not after. Once the coins are in your wallet, their history is yours to explain.

A few things worth doing:

  • Screen the payer's address before you hand over goods, send the work, or quote a price. You want to know whether it's on a sanctions list, whether it's tagged to a hack or a mixer, and whether its recent inflows touch any of those.
  • Be wary of payers whose wallet was funded minutes before the payment, especially through a bridge or a swap service. That's what laundering looks like from the receiving end.
  • Keep a record of the check. If a deposit is ever held, proof that you screened the counterparty before the trade is what gets it released fastest.

If you invoice clients in crypto, you can build this into the invoice itself. A Constatum invoice screens the payer's wallet automatically before the payment is credited to you, so the check happens even on the day you forget.

The freeze on Bitget's stolen funds worked exactly as designed. It stopped $318,000. The rest, hundreds of millions in ETH and bitcoin, is working its way into ordinary wallets, and the only filter left between that money and yours is the one you run yourself.

Sources

  1. 1.[SECURITY NOTICE] Bitget exchange hot wallets Incident — September 2026 — Bitget
  2. 2.Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO says — CoinDesk
  3. 3.Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026 — Elliptic
  4. 4.Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack — TRM Labs
  5. 5.Circle and Tether Freeze Stablecoins Tied to Bitget Hack — Decrypt
  6. 6.Bitget raises breach estimate to $387.5M and launches recovery bounty — Crypto Briefing
  7. 7.Bitget hack sparks dispute over THORChain's permissionless design — crypto.news
  8. 8.Tether Freezes USDT Wallets Linked to Xinbi Network — The Cryptonomist

This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.

Keep reading