UGuardSecurity Desk
BREAKING Sep 25, 2026 · Exchange security incident

Bitget hot wallet hit by unauthorized transfers — about $351.6M affected

On September 25, crypto exchange Bitget confirmed unauthorized transfers from hot wallets. CEO Gracy Chen said its security system flagged abnormal outflows at 02:31 Beijing time; initial estimates put affected funds near $351.6 million. Cold wallets remain secure, user balances were not altered, and the loss can be covered by company funds.

Exchange 2026-09-25 Read original report
Stablecoin asset hooked by a phishing hook — editorial illustration
Malware drained 224 wallets in 48hSession hijacking · $235K+ · Sep 21
USDT 'pig-butchering' ring busted in HunanRigged platform · 2 detained · Sep 21
Liquid Network loses ~4,000 BTC≈ $290M · Sep 07
Tether has frozen ~$4.2B in illicit assets340+ law-enforcement partners · ongoing
01

Latest Intelligence

Newest first · compiled from public reports
09-252026
Exchange$351.6M

Bitget confirms unauthorized hot-wallet transfers, ~$351.6M affected

CEO Gracy Chen said its security system detected abnormal outflows at 02:31 Beijing time; cold wallets remain safe, user balances were not altered, and the loss is coverable by over $464M in company funds.

Sina Finance
09-272026
Fraud ring14 arrested

Qingxu police bust major telecom-fraud ring that rigged fake crypto platforms

Suspects recruited victims through social apps and long-term grooming, then faked trading losses and forced liquidations via back-end control to drain deposits.

FM107 Taiyuan Traffic Radio
09-222026
ResearchRisk note

Data breaches fuel crypto phishing: leaked wallet-service records become social-engineering ammo

Late-summer 2026 leaks exposed ID copies, verification selfies and transaction histories, enabling highly targeted impersonation attacks that pose as official channels.

Sohu · Research digest
09-212026
Malware$235K+

Malware drained 224 crypto wallets in 48 hours, over $235K

A remote-access trojan hijacked user sessions; roughly 224 wallets were compromised. Session hijacking is becoming a major wallet-drain vector.

Coinpedia / 528BTC
09-212026
Pig-butchering2 detained

Hunan police crack USDT 'pig-butchering' scam that lured victims into fake apps

Victims were coaxed into buying USDT on a rigged app before exchanging it for a manipulated new coin; scammers faked price rallies to keep deposits coming.

Red Net
09-072026
Chain incident~4,000 BTC

Liquid Network loses ~4,000 BTC worth about $290M

Exchanges paused LBTC deposits and withdrawals; the network says USDT and other Liquid assets were unaffected. The incident underscores asset isolation.

Phoenix News
09-032026
Phishing7 chains

Malwarebytes warns fake 'GTA 6 leak' site can drain multi-chain wallets

The site ships about 2.4MB of malicious scripts that fingerprint wallets on Ethereum, Polygon, BNB Chain, Avalanche, Arbitrum, Base and Fantom, then move assets based on signed approvals.

ChainCatcher
08-242026
Phishing$550K USDC

Google sponsored ad led to a fake Hyperliquid site — user lost $550K in USDC

Salus tied the case to professional drainer-as-a-service infrastructure linked to the Inferno ecosystem, including malicious scripts, auto-draining and cross-chain withdrawals.

ChainCatcher
05-142026
Freeze$450M+

T3 Financial Crime Unit (Tether × TRON × TRM Labs) freezes over $450M in illicit assets

The joint unit keeps expanding its crackdown on crypto-related financial crime, underscoring how coordinated monitoring supports recovery of stolen USDT.

Tether
04-232026
Freeze$344M

Tether helps freeze $344M in USDT across two addresses at U.S. request

The freeze was executed right after the addresses were identified to stop further movement. Tether reports about $4.2B frozen to date with 340+ agencies.

Tether
03-112026
Law enforcement3.44M USDT

U.S. prosecutors move to seize 3.44M USDT tied to online investment fraud and laundering

The Massachusetts U.S. Attorney's Office filed a civil forfeiture complaint after an investigation begun in late 2024; at least four victims identified.

PANews / Tencent News
03-092026
Attack$24M

SillyTuna attacker begins moving ~$24M in stolen aEthUSDC

PeckShield monitoring shows the attacker deposited about $6.5M in USDC/USDT into centralized exchanges and laundered ETH through mixers.

Wu Blockchain / Sina Finance
02-252026
Recovery$61M

DOJ confirms Tether helped recover $61M in USDT from a pig-butchering fraud

Investigators tracked funds across wallets and, with Tether's help, Homeland Security recovered $61M — proof that stolen stablecoins can be frozen and clawed back.

Tether
02-212025
Record$1.5B

Bybit loses ~$1.5B in ETH — the largest heist in crypto history

Attackers abused a signing-interface flaw to approve transfers from a cold wallet; over 400K ETH/stETH was moved. Chainalysis links the attack to North Korea's Lazarus Group, and the industry launched joint tracking and freezes.

Sina Finance · Chainalysis
02

Data & Report

Chainalysis 2026 Crypto Crime Report & public sources
$17B

Estimated crypto scam & fraud losses in 2025 — a record high (Chainalysis)

+1400%

Year-over-year growth in impersonation scams in 2025

$2.17B+

Stolen from crypto services in H1 2025 — already above all of 2024

$2.02B

Stolen by North Korea-linked hackers in 2025, +51% YoY

$4.2B

USDT frozen by Tether to date, with 340+ law-enforcement partners

Major recent thefts by amount

Log scale · amounts per public reports (USD)
03

How USDT Gets Stolen

Awareness first — know the playbooks

The patterns below are compiled from public cases and security-firm reports (2025–2026). Remember: every scam boils down to tricking you out of your seed phrase / private key / approval, or moving your coins into a platform the scammers control.

TACTIC 01

Fake investment platforms · pig butchering

How it happens: Scammers lure you with "guaranteed returns" or "arbitrage" into a cloned app; early small withdrawals build trust, then back-end controls, forced liquidations or a sudden shutdown take your deposits. Romance-grooming variants push the same script.

RED FLAGSGuaranteed profits · doubled-return promises · "mentor groups" · tax or "security deposit" before withdrawal · app not found in official stores

Cases: Hunan USDT pig-butchering (Red Net) · Zhuzhou "USDT arbitrage" loss of ¥75K (Guangming Daily) · GUCS token fraud ¥1.7B case

TACTIC 02

Phishing sites + search ads

How it happens: Attackers buy Google ads so clone exchanges and wallets rank first, or build bait sites ("leaked game", "airdrop claim") that fingerprint your wallet and move assets once you connect and sign.

RED FLAGSURL differs by a letter · "Ad" tag on results · "connect wallet to claim" prompts · asks for your seed phrase to "verify"

Cases: Google Ads fake Hyperliquid, $550K USDC (ChainCatcher) · fake GTA6 leak site, 7 chains (ChainCatcher)

TACTIC 03

Malicious approvals · wallet drainers

How it happens: Fake platforms show fake balances; to withdraw, they make you connect your main wallet and approve a tiny "test" transaction — the approval triggers an embedded drainer that moves everything to their address, then locks you out.

RED FLAGSWithdrawal requires "approval first" · repeated small test approvals · web-only platform, no real app · no transaction details before signing

Case: Ukraine ring, up to $1M/month, 62 victims (ChainCatcher)

TACTIC 04

Device malware · session hijacking

How it happens: Remote-access trojans enter via shady APKs, cracked software or email attachments and hijack browser/wallet sessions; attackers operate inside your "normal" session and can sweep dozens of wallets in 48 hours.

RED FLAGSDevice runs hot / battery drains · unexpected activity prompts · "security patch" APK installs · approval pop-ups after visiting links

Case: 224 wallets, $235K+ in 48 hours (Coinpedia)

TACTIC 05

Impersonation · social engineering

How it happens: Using leaked data, scammers pose as exchange support, wallet officials or even "government investigators", demanding seed phrases or OTPs, or pushing screen-sharing and phishing logins.

RED FLAGSAnyone asks for seed phrase / private key / OTP · screen sharing requested · "police/support" tells you to move funds to a "safe account" · threats about credit scores

Case: impersonation is one of Singapore's top-3 crypto scams (Tencent News)

TACTIC 06

OTC deals & fake USDT

How it happens: In face-to-face or P2P deals, scammers swap payers ("my friend will pay"), delay or replace payment after receipt, or pass fake USDT minted on non-official contracts — the victim accepts without proper verification.

RED FLAGSLast-minute substitute buyer · insists on off-platform payment · price far below market · "deposit first" demands before delivery

Cases: "friend collects + 1 USDT deposit" trick (Guangming Daily) · Youxian county USDT fraud bust (Guangming Daily)

04

Prevention Guide

Make asset security a habit
Golden shield protecting a stablecoin asset — editorial illustration
Seed phrases and private keys never touch the internet. Write them offline on paper; any website, app or "support" asking for them is a scam.
Keep large holdings in cold wallets. Leave only spending amounts on exchanges and hot wallets to reduce single-point risk.
Reach official sites only from your bookmarks. Don't click search ads or links sent in chats; verify the domain before acting.
Test with a small transfer first. Send 1 USDT to confirm the address before moving large amounts.
Audit your approvals regularly. Revoke unused contract approvals so malicious contracts can't "borrow" your assets.
Verify the USDT contract address. TRC-20 and ERC-20 use different contracts — only official addresses, avoid "fake U".
No unknown APKs, no screen sharing, no sharing OTPs. Trojans hide in cracked packages and "security patches".
Be suspicious of any "guaranteed profit". Sweetener-then-harvest is the standard script; official teams never "run groups" for you.
05

If Your USDT Gets Stolen

Act fast in the golden window
01

Stop the bleeding: move remaining assets

Immediately move untouched assets (same chain or same seed) to a fresh secure wallet; rotate passwords, revoke approvals and sign out suspicious devices.

02

Preserve evidence

Save wallet addresses, transaction hashes (TXIDs), times, amounts, counterparty addresses, chat logs, app download sources and receiving accounts. On-chain evidence is the foundation of tracing and reporting.

03

Report to police + notify exchanges

In China call 110 or anti-fraud hotline 96110; also ask the receiving exchange to freeze the inbound address. The earlier you act, the less chance funds get washed out.

04

Apply to Tether for freezing

Tether's Token Recovery policy accepts claims above $1,000, with fees up to 10% of recovered funds (or $1,000 minimum, whichever is higher); freezes require law-enforcement or judicial requests — file a police report in parallel.

Refs: policy explainer (BlockSec) · case: $650K frozen end-to-end (AMLBot)

05

Professional on-chain tracing

Security firms (e.g., SlowMist MistTrack) can map fund flows and coordinate with exchanges to support law enforcement; the chain is transparent, so stolen funds can be followed.

06

Cooperate with law enforcement

Frozen funds are returned through civil forfeiture or criminal proceedings. Precedents: DOJ-confirmed $61M recovery (Tether) and the U.S. seizure of 3.44M USDT.

06

FAQ

Can stolen USDT actually be recovered?
Yes, but the odds depend on speed and route. Stablecoins are freezable — Tether has frozen about $4.2B in illicit assets and works with 340+ law-enforcement agencies. Report early and loop in the receiving exchange; beware "paid recovery" third parties, which are usually a second scam.
Why do scammers want USDT instead of bank transfers?
USDT trades near 1:1 with the dollar, is globally liquid and easy to move, and its pseudonymous nature suits laundering — but every on-chain transfer leaves a trail that tracing tools and law enforcement can follow. That trail is your best lead for recovery.
I clicked a suspicious link / approved a contract. What now?
Revoke the approval immediately, move affected wallet funds to a fresh wallet, watch for unusual signature requests, and consider a device check. Keep monitoring that address afterward.
"Police / platform support" asked for my seed phrase. Is it real?
No. No agency ever asks for seed phrases, private keys or OTPs, and real police never tell you to move funds to a "safe account" or install software for a "funds review". Hang up and verify through official channels.
Where do the news and data on this page come from?
Every event and figure is cited from the linked public reports and official announcements (Sina Finance, ChainCatcher, Tether, Chainalysis and more). This is an educational security-news digest, not investment advice.