Bitget Hacker Paid Up to 5% Over Spot to Get Out of USDT and USDC as the Fed Writes Stablecoin Reserve Rules
The most useful detail in the Bitget breach is what the attacker did in the first six minutes. Unauthorized transfers began at 18:31 UTC on September 24 with a 0.84 ETH test from a wallet labelled Bitget 6. Within minutes, the USDT, USDC and Tether Gold in the haul were being swapped into ether on Uniswap at prices up to 5% above spot. A thief holding roughly $67M of dollar tokens and $12.8M of tokenized gold accepted up to about $4M of slippage to avoid holding any of it for an hour. Those assets can be frozen by their issuers. Ether can’t. By the time the last transfer landed at 21:23 UTC, about 24,590 ETH sat in three previously unused wallets, and the total loss was confirmed at $351.6M.
On the same afternoon, the Federal Reserve published its proposed rules for stablecoin issuers under the GENIUS Act. The core of it is a 1:1 reserve floor held in cash, Fed balances, bank deposits, Treasury bills with 93 days or less to maturity, qualifying repo and eligible funds, all segregated from the issuer’s own assets. Redemption has to be paid within two business days as a general rule. If backing falls below 1:1, the issuer notifies the Fed and has one quarter to fix it, after which the reserves are liquidated and the tokens redeemed. Compliance is due January 18, 2027. The FDIC has a parallel proposal for the issuers it supervises.
Put the two stories side by side and the attacker’s behaviour reads as a price. The freeze function that makes USDC and USDT unattractive to a thief is part of the same compliance stack the Fed is now formalizing: identified issuers, segregated reserves, and a legal counterparty who can be told to act. The hacker valued the risk of that counterparty at up to 5% of the position and paid it without hesitation. For anyone asking what regulated dollar tokens are worth relative to bearer crypto assets, that is a rare market-priced answer.
Bitget’s own guarantee is a different kind of instrument. CEO Gracy Chen says user funds are safe and that the full loss falls within coverage of the exchange’s User Protection Fund, which holds more than $464M. That’s true on the arithmetic. It also means a single incident consumed about 76% of the fund. Bitget’s August proof-of-reserves showed a 122% ratio across 45 consecutive monthly attestations, and cold storage was untouched; the breach reached only part of the hot and warm wallet layers. Proof of reserves measures assets against liabilities at a point in time. It says nothing about whether the keys to those assets can be taken, and Bitget halted withdrawals while it investigates, a step no issuer under the Fed’s two-day redemption rule would be allowed to take indefinitely. Bitget’s reserve disclosure is better than most offshore venues, and a self-funded guarantee is still is only as deep as the fund’s remaining balance, and after this week that balance is roughly $112M unless the exchange tops it up.
The third story is about which regulator gets to write the guarantee at all. New York Attorney General Letitia James sued Polymarket US, alleging it runs unlicensed gambling in the state, lets 18- to 20-year-olds trade sports contracts when New York requires mobile sportsbook users to be 21, and avoids the taxes licensed sportsbooks pay. The state wants disgorgement, penalties up to three times the alleged gains and $100,000 per unauthorized sports wagering offer. Polymarket countersued the same day in the Southern District of New York, arguing that its contracts are federally regulated swaps traded through QCX, a CFTC-designated contract market, and that Congress barred states from enforcing gambling law against them. It also moved the state’s case into federal court. Polymarket US only launched in December 2025, and it employs more than 350 people in New York.
The legal map is split. The Third Circuit sided with Kalshi against New Jersey in April, finding sports event contracts on CFTC-regulated venues likely count as swaps and preempt state gambling law. The Ninth Circuit went the other way in Nevada in August. New Jersey has asked the Supreme Court to settle it. The CFTC has sued several states, New York among them, to assert exclusive authority, and New York has already sued Kalshi, Coinbase Financial Markets and Gemini Titan over similar products. Polymarket chose a venue where a federal judge declined to block New York’s enforcement against Kalshi in July, which suggests the countersuit is positioning for appeal as much as it is aiming for a quick win in the district court.
The common thread is the federal wrapper. Stablecoins are getting one on explicit terms, with reserve assets, redemption deadlines and a wind-down procedure spelled out. Prediction markets hold one from the CFTC that states are trying to strip. Offshore exchanges like Bitget operate without one and substitute their own funds and attestations. Markets price each arrangement differently, and on September 24 the most honest price came from the attacker, who paid a premium of up to 5% to move out of the wrapped assets.
Bitget has promised a full incident report. The number in it that matters is the protection fund’s balance once the payout is made, and whether the exchange rebuilds it to $464M or leaves it where the hack put it.