Meta Force Space
BTC $84,001.00 -0.69% ETH $2,692.13 -0.14% SOL $121.79 +3.57% XRP $1.57 +2.32% BNB $774.77 -0.79% DOGE $0.0978 +1.39%
← Back to the news

Bitget hacker swaps USDC for ETH as Circle faces renewed freeze questions

The Bitget hacker has converted stolen USDC into ETH after a breach that the exchange valued at about $351.6 million, renewing questions about when Circle freezes funds linked to an attack.

Summary
  • Security researcher Taylor Monahan flagged USDC transfers and swaps tied to the Bitget attacker.
  • Bitget estimated the theft at $351.6 million and temporarily suspended withdrawals.
  • Circle says it freezes USDC when legally compelled, while researchers have criticized its response time in past hacks.
  • A U.S. lawsuit over the Drift exploit has raised similar questions about stolen USDC moving across chains.

Security researcher Taylor Monahan flagged the attacker’s activity on X, pointing to USDC moving through wallets as stolen assets were converted into ETH. Monahan questioned why the funds remained movable despite Circle’s ability to block transfers from specific USDC addresses.

hackers prioritized getting off arbitrum over dumping their usdc lmao

they swapped to usdc

they are holding usdc

they are bridging via cctp

and @circle does nothing

🤡 pic.twitter.com/zmTVjVSa8c

— Tay 💖 (@tayvano_) September 24, 2026

The transactions show the attacker using USDC during the conversion process, according to Monahan’s account. Her criticism concerns Circle’s response to identifiable funds, although the public account of the transfers does not establish whether Circle received a legal order concerning those addresses or when it learned their identities.

Bitget attacker moves USDC after $351.6 million breach

Bitget said its security systems detected unauthorized transfers from some hot wallets at 18:31 UTC on Sep. 24. The exchange activated an emergency response, suspended customer withdrawals and estimated the affected assets at approximately $351.6 million. Deposits and trading remained available, while Bitget said account balances were accurate and its cold wallets were secure.

In its initial report on the breach, crypto.news covered Bitget CEO Gracy Chen’s account of the preliminary investigation. Chen said investigators had ruled out a leak of wallet private keys and believed the attackers had entered the exchange’s systems to move funds directly, without submitting customer withdrawal requests. Bitget was still investigating the entry point and had not released a final account of the attack.

The theft involved several assets, leaving investigators to follow more than one route for the stolen funds. On-chain tracker Lookonchain estimated the stolen portfolio at roughly $356.8 million using prices at the time of its update. Its breakdown included 102.93 million XRP worth about $157.48 million, 31,890 ETH worth about $85.75 million, and 21.05 million USDC. Lookonchain’s changing on-chain estimate and Bitget’s internal loss figure use different measurements.

Bitget said it had flagged addresses linked to the abnormal transfers and notified law enforcement and on-chain security firms. Chen said measures to prevent further outflows had been completed as engineers worked on repairs and the return of withdrawal services.

Monahan’s concern centers on the portion of the stolen assets held in USDC. Circle’s USDC terms say the issuer reserves the right to block transfers to and from certain on-chain addresses under its blocklisting policy. Once an attacker swaps USDC for ETH, however, a block on a USDC address cannot freeze the ETH received in that trade.

Circle’s freeze policy draws a response-time dispute

Circle has described a narrower standard for using its technical controls than the one its critics seek during a live exploit. In an April statement on lawful intervention, published after the Drift Protocol hack, the company said it exercises its freeze ability when legally compelled by an appropriate authority. Circle argued that letting an issuer decide on its own whose assets to block could put legitimate holders’ property rights at risk.

Its USDC terms also say Circle may be required to freeze tokens after receiving a legal order from a valid government authority. The terms separately reserve the right to block certain addresses that Circle determines may be associated with illegal activity or a violation of its terms. They state that an on-chain USDC transaction cannot be reversed or recalled once initiated.

Those provisions matter to U.S. holders because Circle issues a dollar-backed stablecoin used across exchanges and decentralized applications, while its freeze decisions can affect access to tokens at a particular address. Circle’s stated policy places lawful process at the center of that decision. Monahan’s criticism focuses on the time available to intervene before a suspected attacker finishes moving or swapping the USDC.

Circle said in its April statement that tools for faster intervention exist, but legal frameworks for quicker, coordinated action while protecting users’ rights remain incomplete. The company called for clearer rules and for security measures across protocols, wallets, exchanges and stablecoin issuers.

ZachXBT documented 15 earlier USDC cases

On-chain investigator ZachXBT alleged in April that Circle had taken minimal action or failed to act quickly enough in 15 cases involving more than $420 million in suspected illicit USDC flows since 2022. His list covered hacks and fraud cases in which he said stolen funds remained movable despite time to identify the activity.

As previously covered by crypto.news, ZachXBT cited about $9 million in USDC linked to the July 2025 GMX hack and said wallets involved in the Cetus hack were blocked only after the stolen USDC had been converted into ETH. He also alleged that attackers in the Drift case moved roughly $232 million over about six hours and more than 100 transactions before converting the funds.

The Drift transfers became the subject of a U.S. civil case. In April, a claimant sued Circle over transfers following the exploit, alleging that the issuer failed to stop roughly $230 million in stolen USDC routed through its Cross-Chain Transfer Protocol. The complaint, filed in a federal district court in Massachusetts, argues that earlier intervention could have reduced the losses. Those are the claimant’s allegations, rather than a court finding against Circle.

In that case, the claimant also pointed to Circle’s freeze of 16 USDC-linked wallets tied to a separate sealed U.S. civil matter as evidence that the issuer could block addresses. Circle’s April public statement, issued after the Drift attack, said freezes require lawful authority and called for legal structures that would permit faster action during future incidents.

Originally published by crypto.news on

Read the original on crypto.news ↗

Text and images are the property of crypto.news and are reproduced here with attribution and a link to the original publication.

More stories

All the latest news