ZachXBT Accuses Circle of Delayed Freezes in Stolen USDC Cases Tied to Over $420 Million in Losses

ZachXBT Accuses Circle of Delayed Freezes in Stolen USDC Cases Tied to Over $420 Million in Losses

N
News Editor 01
2026-07-22 11:40:13
ZachXBT says Circle repeatedly failed to freeze stolen USDC in time, with more than $420 million in losses across major hacks involving Drift Protocol, Bybit, Radiant Capital, Mango Markets, and Nomad Bridge.
CircleUSDCZachXBTon-chain securityhacks

Blockchain investigator ZachXBT has publicly accused USDC issuer Circle of failing to freeze stolen funds quickly enough in a string of major hacks, saying the pattern has contributed to more than $420 million in losses over the past three years. In a long thread titled “Welcome to Circle Files,” he argued that the issue is not a one-off mistake but a repeated compliance failure across several widely known incidents.

Drift Protocol exploit is the latest flashpoint

One of the most recent examples in the thread is the April 1, 2026 exploit involving Drift Protocol. ZachXBT said more than $232 million in USDC was bridged from Solana to Ethereum in over 100 transactions across six hours, using Circle’s own Cross-Chain Transfer Protocol, without a freeze from Circle. Security researcher Specter said the attacker deliberately avoided converting the funds into Tether during the process, a detail he took as a sign that the hacker did not expect Circle to step in quickly.

Bybit, Radiant, Mango, and Nomad are also cited

ZachXBT’s thread ties that case to a broader record. In the February 2025 Bybit hack, when the Lazarus Group stole $1.5 billion, law enforcement asked both Tether and Circle to freeze a theft address. According to the post, Tether acted within hours, while Circle moved about 24 hours later.

He also pointed to the October 2024 Radiant Capital attack, where the Lazarus Group stole $58 million. The attackers used open approvals to take USDC and moved the funds across multiple blockchains. The funds reportedly remained in hacker-controlled wallets for hours, yet Circle did not freeze them. In the October 2022 Mango Markets hack, the attacker sent $57.5 million to a Circle deposit address on Solana and later moved the funds to Ethereum. The attacker was later charged by the SEC, but the stolen funds were never frozen on-chain.

The thread also revisits the August 2022 Nomad Bridge hack. About $45 million in USDC sat in hacker wallets for roughly 30 to 45 minutes after the incident had already become public, yet Circle never blacklisted the addresses and the funds were swapped out.

The dispute centers on speed, not capability

ZachXBT’s central argument is that Circle had the tools to act and did not use them fast enough. The material says the USDC token contract includes freeze and blacklist functions, and Circle’s own terms of service state that it may restrict access for suspected illicit actors at its “sole discretion.”

On that basis, the claim is that Circle does not need to wait for a court order before freezing stolen USDC. ZachXBT’s criticism is narrower and more direct: in cases where the theft was public and the on-chain movement was traceable, Circle repeatedly delayed action, leaving victims without a chance to stop the funds before they were moved away.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.