Security researcher Taylor Monahan flagged the suspicious activity on X, highlighting how the stolen assets were shuffled across wallets and bridged via the Cross-Chain Transfer Protocol. While Bitget confirmed the breach occurred at 18:31 UTC on September 24 and subsequently suspended withdrawals, the movement of funds has intensified pressure on Circle to utilize its blacklisting capabilities. Circle maintains that it only freezes USDC when legally compelled by appropriate authorities, arguing that unilateral intervention could jeopardize the property rights of legitimate token holders. This stance remains a point of friction for investigators who contend that the issuer’s deliberate pace allows attackers to swap stablecoins for decentralized assets like ETH, effectively rendering a later freeze on the USDC address useless.
The industry tension mirrors a recent civil lawsuit involving the Drift Protocol exploit, where claimants argued that Circle’s failure to act enabled the movement of roughly $232 million. On-chain investigator ZachXBT has previously documented 15 cases involving over $420 million in suspected illicit USDC flows, alleging that Circle consistently fails to intervene until after funds are converted. Bitget CEO Gracy Chen stated that investigators have ruled out a private key leak, suggesting instead a sophisticated backend breach. While Bitget continues to work with law enforcement and security firms to track the stolen portfolio—which includes significant holdings of XRP and ETH—the attacker’s ability to remain active on-chain leaves the broader ecosystem questioning the balance between legal due process and the necessity of rapid security intervention.

Comments (0)
No comments yet. Be the first!