Blockchain investigator ZachXBT publicly criticized Circle for failing to freeze stolen USDC as it moved through the company’s own cross-chain infrastructure during the $285 million Drift Protocol exploit on April 1. The attacker bridged tens of millions of dollars in USDC from Solana to Ethereum using Circle’s Cross-Chain Transfer Protocol over a period of several hours, all during U.S. business hours, without any intervention from the stablecoin issuer.

“Circle was asleep while many millions of USDC were swapped via CCTP from Solana to Ethereum for hours from the 9-figure Drift hack during US hours,” ZachXBT wrote on X. Security researcher Specter added that the attacker held USDC across multiple wallets for one to three hours before converting it, and deliberately avoided routing through Tether, suggesting the attacker was confident Circle would not act.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


The backlash is amplified by Circle’s actions in a recent incident. On March 23, the company froze USDC balances across 16 unrelated business hot wallets as part of a sealed U.S. civil case. The affected wallets belonged to active commercial operations, including exchanges, casinos, forex brokers, and payment processors. One turned out to be the ckETH Minter Smart Contract operated by the DFINITY Foundation, a bridge connecting Ethereum to the Internet Computer Protocol. ZachXBT called that freeze “potentially the single most incompetent” he had witnessed in five years of onchain investigations.

The contrast between the two incidents has reignited debate over centralized stablecoin governance. Critics argue that if Circle claims the authority to freeze assets at the smart-contract level, it must apply that power consistently, not aggressively against legitimate businesses while ignoring a confirmed nine-figure exploit transiting its own infrastructure.

Circle has not publicly addressed the criticism regarding the Drift hack.