Tether freezes 218,000 USDT tied to $351.6 million Bitget hack
Tether has frozen 218,000 USDT linked through three transaction steps to the wallet associated with the Bitget theft, following an earlier freeze of related funds by Circle as stablecoin issuers move to contain assets connected to the $351.6 million exchange breach.
Tether froze 218,000 USDT connected to the Bitget theft on September 25, 2026, acting roughly seven hours after Circle had already frozen related funds.
The USDT had sat untouched at the flagged address for more than 2.5 hours before Tether intervened, giving investigators a window to act before the funds could move further.
Tether freezes funds tied to Bitget theft
The 218,000 USDT freeze concerns funds held at an address connected to the original Bitget theft wallet through three transaction steps.
The movement of the funds is significant because stablecoins such as USDT and USDC can, under certain circumstances, be frozen by their issuers when addresses are identified as being connected to illicit activity or stolen assets.
In this case, Tether’s intervention followed Circle’s earlier action on related funds. The timing points to parallel efforts by the two major stablecoin issuers to restrict the movement of assets believed to be associated with the Bitget incident.
The funds had reportedly remained unmoved for more than 2.5 hours after their connection to the Bitget theft was identified. That delay provided a window for the issuer to take action before the assets could potentially be transferred, swapped or bridged to another blockchain.
The freeze does not recover the entire amount involved in the Bitget theft. Instead, it represents a targeted effort to prevent a portion of the stolen assets from moving further through the crypto ecosystem.
Bitget theft involves $351.6 million in assets
Bitget disclosed the security incident after its systems detected unauthorized transfers at 18:31 UTC on Sept. 24. The exchange said the incident was confined to part of its hot and warm wallet infrastructure, while its cold wallets remained secure.
According to Bitget, approximately $351.6 million in assets were affected. The exchange said its User Protection Fund, which it valued at more than $464 million, was sufficient to cover the reported loss. It also temporarily suspended withdrawals as its security team investigated the incident.
The exchange said deposits and trading remained operational and that customer account balances were accurate. It also said relevant transfer addresses had been identified and flagged, with law enforcement agencies and blockchain security firms notified.
The scale of the Bitget theft initially appeared smaller when blockchain researchers tracked only the assets visible on publicly labeled exchange wallets. The Block reported that more than $170 million had moved from wallets labeled as belonging to Bitget into a newly created address before the exchange confirmed the broader incident.
Later reporting and Bitget’s own assessment put the total affected amount substantially higher.
The stolen assets reportedly included ETH, USDT, USDC, AVAX and BNB, among other tokens. On-chain analysis also showed some of the assets being swapped and moved between networks, complicating efforts to trace and recover them.
Stablecoin issuers move against stolen funds
The reported Tether freeze came after Circle had already frozen related funds, creating what appears to be a coordinated containment effort across two major dollar-pegged stablecoins.
The reported Tether freeze came after Circle had already frozen related funds.
However, freezing stablecoins does not necessarily mean the stolen assets can immediately be returned to Bitget. The funds remain subject to the broader investigation, including tracing the transactions, identifying the parties controlling the receiving addresses and determining how the stolen assets moved through different networks.
The Bitget theft also demonstrates why speed matters in blockchain investigations. Once stolen stablecoins are converted into assets such as ETH or moved through bridges and decentralized exchanges, intervention by a centralized issuer becomes considerably more difficult.
Investigation into Bitget theft continues
Bitget has said it activated an emergency response team within minutes of detecting the unauthorized transfers and has engaged law enforcement and on-chain security firms. The exchange also said it would publish a full incident report covering the root cause and corrective measures.
The exact attack mechanism remains under investigation. Bitget has said it will not speculate on the attack vector while the investigation is ongoing.
Separate reporting has highlighted preliminary claims about possible links to North Korea-associated hacking activity, but those claims remain an attribution under investigation rather than an established finding. Cointelegraph reported that Bitget CEO Gracy Chen cited preliminary similarities involving IP addresses and VPN services, while noting that the attackers’ identity had not been confirmed.
For now, the Tether freeze represents one of the clearest interventions stemming from the Bitget theft. The 218,000 USDT is only a small portion of the total reported loss, but its immobilization shows how blockchain tracing and issuer-level controls can be used to contain stolen digital assets.
As Bitget continues its investigation and blockchain researchers follow the remaining funds, further freezes could become possible if additional USDT or USDC linked to the Bitget theft is identified before it is converted or moved beyond the reach of centralized issuers.
The immediate focus remains on tracing the stolen assets, determining the full attack path and restoring normal withdrawal operations at Bitget.
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.