One of the most important lessons in crypto security is that stolen funds are not always easy to stop. Even when an exchange is hit by a large-scale hack, the response is rarely simple. In the case of the recent Bitget crypto heist, stablecoin issuers Circle and Tether moved quickly to blacklist a hacker wallet holding about $318,000 in USDT and USDC. That action was significant, but it also highlighted a major limitation in the crypto world: most of the stolen funds were reportedly held in ether, and ether cannot be frozen in the same way.
The incident raises a broader question that has come up repeatedly in crypto security incidents: why are some assets easier to stop than others? The answer lies in how stablecoins differ from major decentralized cryptocurrencies like Ethereum.
What Happened in the Bitget Heist
Following a massive theft from Bitget, Circle and Tether reportedly took action against a wallet associated with the hacker. The blacklisted address held approximately $318,000 in stablecoins, including both USDT and USDC. By blacklisting the wallet, the stablecoin issuers effectively limited the hacker’s ability to move or use those funds in connected ecosystems where the issuers can enforce restrictions.
That response was notable because stablecoin issuers do not have the same level of control over all crypto assets. In fact, their ability to freeze certain addresses is one of the reasons stablecoins are often viewed differently from native cryptocurrencies. They are not fully permissionless in the way that ether or bitcoin are. Circle and Tether maintain off-chain systems that can restrict movement of funds tied to specific addresses, which makes them useful in incident response.
Why Stablecoins Can Be Frozen
Stablecoins such as USDC and USDT are backed by off-chain reserves and operate with a degree of centralization. While they exist on public blockchains, their issuers can maintain control over certain actions, including blacklisting addresses or freezing tokens transferred to sanctioned or malicious wallets.
That capability is one of the reasons stablecoins have become so dominant in crypto exchange operations, DeFi lending, trading pairs, and treasury management. Exchanges and users rely on them for stability, liquidity, and ease of use. But that same structure can also be used defensively when funds are stolen.
In practical terms, if a hacker tries to move frozen stablecoins into an exchange or DeFi protocol that respects the blacklist, the transfer may be blocked or the funds may be rendered unusable. That does not erase the theft, but it can reduce the attacker’s options for cashing out.
Why Ether Is Much Harder to Stop
The bigger problem in this incident is that most of the stolen funds were not in stablecoins. They were reportedly held in ether, which is a native asset on the Ethereum network. Unlike stablecoins, ether cannot be frozen by a central issuer because it is not tied to a permissioned off-chain ledger in the same way.
Ethereum is a decentralized network. Its value comes from transparency, trustlessness, and the fact that no single company can simply stop a legitimate transaction. That is one of its greatest strengths, but it also makes stolen ether far more difficult to recover. A hacker can move ether between wallets, swap it for other tokens, bridge it to another chain, or use it in decentralized applications.
In many theft scenarios, attackers do not simply sit on the stolen funds. They move quickly to convert, bridge, and obscure the trail. That is why freezing a stablecoin wallet helps, but it is not a complete solution when the majority of the stolen assets are in a non-freezable asset like ether.
What This Means for Crypto Exchanges
High-profile exchange hacks continue to expose the same core tension in crypto: decentralization makes the system trustworthy, but it also makes theft recovery more complicated. Exchanges hold enormous amounts of user funds, and when those funds are at risk, the response depends heavily on the type of assets involved.
If a hacker steals stablecoins, there is at least a chance that issuers can limit the damage. If the stolen funds are in bitcoin or ether, recovery becomes far more difficult. That reality has pushed many exchanges to rethink how they manage hot wallets, withdrawal limits, treasury diversification, and risk controls.
Some of the key lessons from incidents like this include:
- Hot wallets should hold only what is needed for operations. Keeping large amounts of user funds in wallets that are connected to the internet increases risk.
- Withdrawal limits and monitoring matter. Early detection can slow down a hacker’s ability to move funds.
- Stablecoin exposure is not neutral. Stablecoins offer liquidity, but they also create a different set of risk and recovery dynamics.
- DeFi and bridge activity can complicate recovery. Once stolen ether enters decentralized finance, it can become much harder to trace or freeze.
The Bigger Takeaway
The Bitget heist shows that crypto security is not just about preventing the initial breach. It is also about what happens after the funds are stolen. Circle and Tether were able to act against a wallet holding roughly $318,000 in stablecoins, and that response likely reduced the attacker’s ability to use part of the stolen funds. But the fact that most of the stolen assets were in ether underscores a persistent challenge in the industry.
Stablecoins can be frozen. Ether cannot. That distinction matters enormously in real-world theft cases. For exchanges, users, and regulators, the incident is a reminder that asset choice, wallet design, and incident response are all part of the same security problem. In crypto, prevention is still far easier than recovery, especially when the stolen funds are held in one of the most decentralized assets on the market.
Related read: Strategy Seeks Shareholder Approval for Daily Dividends on STRC and Other Preferred Stocks
