Circle and Tether Freeze Stablecoins After Bitget Hack
When the Bitget exchange was hit by a significant exploit in late September 2026, two of the world's largest stablecoin issuers responded by blacklisting wallet addresses linked to the stolen funds. Circle, the issuer of USDC, and Tether, the issuer of USDT, each exercised their on-chain freeze powers to render those stablecoins immovable. The intervention worked, but only partially: most of the broader sum involved in the incident had already dispersed across other assets and chains before the freeze orders took effect. The episode crystallises a compliance reality that every accounting firm, auditor, and CFO working with digital assets needs to understand and build into their processes right now.
What Happened at Bitget
Bitget, a centralised crypto exchange with a substantial global user base, suffered a security breach that resulted in a material outflow of funds. Attackers moved quickly, converting stolen assets and routing proceeds across multiple wallets. Among the assets involved were significant quantities of USDC and USDT, the two dominant dollar-pegged stablecoins by market capitalisation.
The freeze response
Circle and Tether each operate a compliance function that can blacklist specific Ethereum-compatible addresses, rendering any stablecoins sitting at those addresses untransferable. Both issuers acted after being notified of the hack, freezing addresses associated with the exploit proceeds. This is not a novel capability: Tether has exercised it in prior high-profile enforcement situations, and Circle's USDC smart contract contains an equivalent mechanism. What made this incident instructive was the outcome: the freeze captured only a portion of the illicit flow. The attacker had already swapped or bridged a substantial share of the funds into assets and networks that neither issuer could touch.
Why the gap matters
The time between an exploit being detected, an exchange notifying issuers, issuers verifying the claim, and a freeze actually executing on-chain can run to several hours. In crypto markets, several hours is more than enough time to move funds across bridges, swap into non-freezable assets such as ETH or BTC, or deposit into mixers and privacy-preserving protocols. The Bitget incident illustrates that stablecoin freeze mechanisms are a meaningful but time-bounded enforcement tool, not a comprehensive recovery mechanism.
The Issuer Freeze Power: Scope and Limits
Understanding exactly what Circle and Tether can and cannot do is essential for any firm advising clients on stablecoin risk or holding stablecoins in a treasury or custody context.
What issuers can freeze
Both Circle (USDC) and Tether (USDT) embed blacklist functionality directly in their token smart contracts. An issuer can designate a wallet address as frozen, after which any attempt to transfer tokens from that address fails at the contract level. The issuer can also, in some cases, destroy frozen tokens and reissue an equivalent amount to a recovery address, subject to legal process. These powers apply to tokens on all chains where the issuer has deployed and controls the canonical contract, which covers Ethereum, Tron (dominant for USDT), and a range of other networks.
What issuers cannot freeze
Once funds leave the stablecoin entirely, the issuer's reach ends. An attacker who swaps USDC for ETH on a decentralised exchange holds ETH, and no freeze mechanism touches that position. Bridged funds that arrive on a chain where the issuer does not control the canonical contract, or wrapped versions of stablecoins issued by third parties, are similarly beyond direct reach. Privacy coins and mixer outputs fall entirely outside this enforcement perimeter. This structural gap is why the majority of funds in the Bitget incident are reported to have escaped.
Accounting Implications for Firms and CFOs
The freeze event creates a set of accounting questions that firms need to answer, preferably before a crisis rather than during one. Whether a firm is an exchange, a treasury operation holding stablecoins as near-cash, or an accountant preparing financial statements for a digital asset business, the classification and disclosure of frozen assets matters.
Classifying frozen stablecoins
A stablecoin that is frozen is, by definition, not liquid. Under IFRS, an asset classified as cash or a cash equivalent must be readily convertible to a known amount of cash and subject to an insignificant risk of changes in value. A frozen stablecoin fails the convertibility test: it cannot be transferred or redeemed while the freeze is in force. Firms should therefore reclassify frozen stablecoins out of cash equivalents and into a separate financial asset category, subject to any impairment assessment that reflects uncertainty about recoverability. Under US GAAP, the analysis is similar: ASC 350-60 now requires fair value measurement for most digital assets, but fair value presupposes an orderly transaction, which is not available for a frozen asset. A frozen balance will likely require a specific disclosure and potentially a fair value adjustment to reflect the restriction.
Custody and client reporting obligations
Accounting firms that use crypto accounting software to manage client portfolios containing stablecoins need a documented process for handling freeze events. If a client's stablecoins are frozen as a result of their exchange being hacked (even as an innocent third party), the firm needs to: flag the affected balance immediately in the client's ledger, adjust any cash or liquidity reporting that relies on those balances, and assess whether the freeze constitutes a subsequent event requiring disclosure if it occurs close to a reporting date. Digital asset accounting software that does not surface real-time address-level status creates a material gap in this workflow. The Bitget incident is a concrete case study for why address monitoring is not optional.
Tax treatment of frozen assets
A freeze does not, by itself, constitute a disposal for tax purposes in most jurisdictions. The asset has not changed hands; it is simply immobilised. However, if frozen tokens are subsequently destroyed and reissued to a different address as part of a legal recovery process, that destruction and reissuance may constitute a taxable event depending on jurisdiction. Firms advising clients who hold stablecoins on affected platforms should document the position carefully and seek specific guidance where the regulatory framework is unclear. The UK's HMRC, the IRS in the US, and most EU tax authorities have published guidance on crypto disposals, but the specific treatment of court-ordered or issuer-directed token destruction remains an area where professional judgement is required.
AML and Compliance Obligations for Firms
The Bitget hack also carries AML implications that extend beyond the exchange itself. Any firm that received funds from the affected wallets, even unknowingly and even before the freeze was imposed, may have inadvertently processed proceeds of crime.
Tracing and taint analysis
Regulated firms, including crypto exchanges, brokers, and any Virtual Asset Service Provider subject to FATF-aligned rules, are expected to conduct ongoing transaction monitoring. Where blockchain analytics identifies that a counterparty wallet received funds traceable to a known exploit, the receiving firm has an obligation to assess whether a Suspicious Activity Report or equivalent filing is required. The fact that the tainted funds arrived before a freeze was publicly announced does not eliminate the retrospective reporting obligation. Firms need crypto bookkeeping software and compliance tooling that can ingest address-level risk flags from recognised blockchain analytics providers and tie them to specific ledger entries.
Policy and procedure gaps this incident exposes
Three specific gaps tend to appear in post-incident reviews of this type. First, the absence of a documented stablecoin freeze response procedure: who is notified internally, who assesses the accounting impact, and who communicates with the issuer or exchange. Second, over-reliance on stablecoins as liquid assets without a stress scenario that accounts for freeze risk. Third, no clear escalation path in digital asset accounting software when an address flag arrives mid-period. Firms that address these gaps before the next incident will be better placed to satisfy both regulator expectations and client obligations. For further context on how AML detection methods for suspect crypto wallets are evolving, the behavioural detection frameworks covered in our earlier analysis remain highly relevant.
Broader Enforcement Context
Circle and Tether acting in concert in response to an exchange hack is a sign of a maturing, if still imperfect, enforcement ecosystem. Stablecoin issuers are increasingly treated as a de facto compliance layer within the crypto market structure, a role that regulators have noted approvingly. The European Banking Authority, in its ongoing work under MiCA, has been explicit that e-money token issuers must maintain the ability to freeze or restrict tokens in response to legal or regulatory demands. The practical implication for firms operating under MiCA or advising MiCA-regulated entities is that freeze risk is now a codified feature of the stablecoin landscape, not an exceptional measure.
For UK firms, the FCA's cryptoasset authorisation regime similarly expects regulated firms to demonstrate robust procedures for handling frozen or disputed digital assets. Understanding how the FCA cryptoasset authorisation gateway affects UK firms is therefore directly relevant to any compliance programme that includes stablecoin exposure.
Practical Steps for Accounting Firms and CFOs
The following actions are appropriate responses to the Bitget incident for any firm with stablecoin exposure in client or proprietary accounts.
Immediate review items
Confirm whether any client or house accounts held stablecoins on Bitget or in wallets that received funds from affected addresses around the time of the incident. Pull address-level transaction data from your crypto accounting software and cross-reference against published freeze lists. Document the results, including nil findings, as evidence of due diligence.
Policy updates
Draft or update a stablecoin freeze response procedure that assigns clear ownership across your compliance, accounting, and client-facing teams. Ensure your digital asset accounting software can apply a "restricted" or "frozen" tag to specific address balances and that this tag flows through to reporting outputs automatically. Review your cash and liquidity disclosures to confirm they exclude or separately identify any assets that are subject to transfer restrictions.
Client communication
Where clients hold material stablecoin balances on centralised exchanges, this incident is an opportunity to discuss custodial risk, the difference between exchange-held and self-custied stablecoins, and the accounting treatment that would apply if a freeze event affected their holdings. That conversation is also a natural entry point for reviewing whether the firm's current crypto bookkeeping software provides sufficient address-level transparency to support rapid incident response.
Source: Decrypt
Frequently Asked Questions
Can Circle or Tether freeze my stablecoins even if I am not involved in a hack?
Yes. Both issuers reserve the right to freeze addresses in response to legal orders, regulatory demands, or credible reports of illicit activity. An innocent holder whose address receives tainted funds, or whose address is incorrectly flagged, can in principle be caught by a freeze. Contacting the issuer directly and engaging legal counsel is the appropriate response if this occurs.
How should a frozen stablecoin balance appear in financial statements?
A frozen stablecoin should be removed from cash and cash equivalents because it is not freely transferable. It should be reclassified as a financial asset subject to restriction, with disclosure of the nature and expected duration of the freeze. An impairment assessment may also be required if recovery is uncertain.
Does a stablecoin freeze create a taxable event?
A freeze alone is generally not a disposal and therefore not a taxable event in most jurisdictions. However, if frozen tokens are subsequently destroyed and reissued as part of a recovery process, that step may constitute a taxable disposal depending on the applicable tax authority's treatment. Specific advice should be sought in the relevant jurisdiction.
What AML obligations arise if a firm unknowingly receives funds from a hacked exchange?
Regulated firms are expected to conduct retrospective transaction monitoring when new information, such as a published freeze list or law enforcement alert, identifies a counterparty as linked to illicit activity. Where tainted funds are identified, the firm should assess whether a Suspicious Activity Report or equivalent filing is required, freeze or restrict the affected balance pending further review, and document the steps taken.
Why do most exploit funds escape despite stablecoin freezes?
The principal reason is speed. Attackers typically convert stablecoins into non-freezable assets or move funds across bridges within minutes or hours of an exploit. The time required for an exchange to detect the breach, notify issuers, and for issuers to execute the on-chain freeze is often longer than this window. Freeze mechanisms are effective for funds that remain in the original stablecoin at the original address, but they cannot reach assets that have already been swapped or bridged.
