‘The Circle USDC Files’: ZachXBT Finds $420M In Suspect Transactions, Weak Oversight

bitcoinistPublished on 2026-04-04Last updated on 2026-04-04

Abstract

On-chain investigator ZachXBT's report, "The Circle USDC Files," alleges over $420 million in compliance failures by Circle related to its stablecoin USDC since 2022. The report claims Circle repeatedly failed to use its on-chain freezing and blacklist functions to halt stolen funds in high-profile DeFi exploits, despite having the contractual right and technical capability to do so. Notable cases include the April 2026 Drift Protocol hack ($280M) and the January 2026 SwapNet attack ($16M), where Circle allegedly delayed or refused freeze requests from law enforcement and analysts. Compared to other stablecoin issuers, Circle was significantly slower to act, taking months longer to freeze addresses in some instances. ZachXBT argues this pattern of inaction has caused nine-figure losses to the crypto ecosystem.

On-chain investigator ZachXBT has published a new report, titled “The Circle USDC Files,” alleging more than $420 million in compliance failures tied to the company’s USDC stablecoin since 2022.

The analysis, released on social media platform X on Friday, chronicles multiple high‐profile decentralized finance (DeFi) exploits in which Circle allegedly failed to use its on‐chain freezing and blacklist capabilities to halt the flow of stolen funds.

Alleged Inaction By Circle

Circle’s token contract includes an explicit freeze/blacklist function, and the company’s terms of service reserve the right to restrict access for suspected illicit actors “in its sole discretion.”

Yet, ZachXBT’s report claims that in many widely reported thefts and hacks, the issuer either delayed action or did not freeze funds at all, allowing attackers to move large sums across blockchains and convert them into other assets.

The report opens with the April 1, 2026, Drift Protocol exploit, in which the attacker drained roughly $280 million. According to ZachXBT, the thief used Circle’s Cross‐Chain Transfer Protocol (CCTP) to bridge more than 232 million USDC from Solana (SOL) to Ethereum (ETH) in over 100 transactions.

The incident had ripple effects across the Solana ecosystem, indirectly impacting more than 10 DeFi projects. Despite the funds moving through Circle’s native bridge for hours, the report says no USDC was frozen during the laundering.

ZachXBT also details a January 25, 2026, attack on SwapNet that resulted in $16 million being stolen. Roughly $3 million in USDC remained in the exploiter’s address for two days. Both law enforcement and private‐sector analysts reportedly submitted temporary freeze requests to Circle for that address, but Circle did not act.

Nine‐Figure Losses In Crypto Hacks

Among several other cases cited in the report, ZachXBT also points to broader, long‐running patterns. In April 2024, he published a separate investigation into the Lazarus Group laundering that traced funds from more than two dozen hacks being converted to fiat.

Law enforcement requested freezes from four stablecoin issuers — Circle, Tether, Paxos, and Techteryx — for two addresses tied to that investigation. The report claims the other three issuers acted quickly, while Circle took approximately 4.5 months longer to freeze the same addresses.

Taken together, ZachXBT says these cases — many of them public and high‐value — add up to nine‐figure losses to the crypto ecosystem caused by repeated inaction over a multi‐year period.

He stresses that the $420 million-plus figure covers only major public incidents and that the true total could be substantially higher. The overarching claim is that Circle possesses the contractual and technical tools to intervene, yet has not used them consistently or promptly, with concrete harm to victims and the broader community.

“They have every tool and resource available to do better. They just haven’t,” he writes, closing his report with a pointed question: who, exactly, is Circle serving?

The daily chart shows CRCL’s valuation at around $90 at the time of writing. Source: CRCL on TradingView.com

Featured image from OpenArt, chart from TradingView.com

Related Questions

QWhat is the main allegation in ZachXBT's report titled 'The Circle USDC Files'?

AThe report alleges more than $420 million in compliance failures tied to Circle's USDC stablecoin since 2022, claiming the company failed to use its on-chain freezing and blacklist capabilities to halt the flow of stolen funds in multiple high-profile DeFi exploits.

QAccording to the report, what specific tool did Circle allegedly fail to use effectively in the Drift Protocol exploit?

ACircle allegedly failed to use its on-chain freeze/blacklist function and its Cross-Chain Transfer Protocol (CCTP) to stop the attacker from bridging over 232 million USDC from Solana to Ethereum in over 100 transactions, despite the funds moving for hours.

QHow did Circle's response time to a law enforcement freeze request compare to other stablecoin issuers in the Lazarus Group case?

AThe report claims that while Tether, Paxos, and Techteryx acted quickly on the law enforcement request, Circle took approximately 4.5 months longer to freeze the addresses tied to the investigation.

QWhat does ZachXBT suggest is the total financial impact of Circle's alleged inaction?

AZachXBT states that the cases add up to nine-figure losses (over $100 million) to the crypto ecosystem, with the $420 million-plus figure covering only major public incidents, and the true total potentially being substantially higher.

QWhat contractual right does Circle's Terms of Service reserve regarding suspected illicit actors?

ACircle's Terms of Service reserve the right to restrict access for suspected illicit actors 'in its sole discretion,' granting the company the authority to freeze or blacklist addresses.

Related Reads

Defending Champions or New Kings? World Cup Final Sees All AIs Backing the Same Side

Will the 2026 World Cup final see Argentina successfully defend their title or a new champion crowned? AI models from various platforms have made their prediction. The final in Buenos Aires pits defending champions Argentina against a resilient Spanish side that has reached this stage with a record of exceptional defensive solidity, conceding only one goal in seven matches. Argentina's path was dramatically different, filled with late comebacks and narrow victories, including a semi-final win over England secured by late goals assisted by the 39-year-old Lionel Messi. A poignant subplot adds narrative weight: a nearly 20-year-old photo shows a young Messi bathing an infant Lamine Yamal, who is now a 19-year-old key player for Spain, symbolizing a potential passing of the torch. In the semi-finals, most AI models incorrectly predicted a French victory over Spain, with only Google's Gemini correctly picking Spain's advancement and also accurately forecasting Argentina's win over England. For the final, however, all six surveyed AIs—ChatGPT, Claude, Gemini, Grok, DeepSeek, and Qwen—unanimously predict a Spanish victory. Their reasoning centers on Spain's superior defense, midfield control, and better physical preparedness after a less strenuous knockout stage journey. While consensus favors Spain as champions, five of the six AIs believe the match will be tightly contested, predicting a draw (1-1 or 0-0) within regular time, with Spain's advantage potentially telling in extra time or even a penalty shootout. Only DeepSeek forecasts a clear Spanish victory within 90 minutes. The stage is set for a clash between Argentina's legendary fighting spirit and Spain's machine-like consistency, with artificial intelligence firmly backing the latter to lift the trophy.

Odaily星球日报16m ago

Defending Champions or New Kings? World Cup Final Sees All AIs Backing the Same Side

Odaily星球日报16m ago

From a Loss of 19.2 Billion to a Profit of 7.1 Billion, ChangXin Technology States 'Downturn Cycle Remains a Concern'

Changxin Technology, China's leading domestic DRAM manufacturer, is nearing its IPO on the STAR Market. After reporting significant net losses of -192.25 billion yuan and -90.51 billion yuan in 2023 and 2024 respectively, the company achieved a net profit of 71.44 billion yuan in 2025. This turnaround is attributed to an AI-driven surge in DRAM demand and tight industry supply, leading to a 33.69% increase in average selling prices alongside reduced unit costs. Despite the improved profitability, with gross margins rising from -1.93% in 2023 to 40.99% in 2025, Chairman Zhu Yiming cautions that the strongly cyclical DRAM industry remains vulnerable. Risks include potential macroeconomic shifts, uncertain AI demand, and new capacity expansions that could trigger another downturn. The company still faces high fixed costs, with depreciation reaching 246.8 billion yuan in 2025. Changxin plans to raise 29.5 billion yuan through its IPO to fund technology upgrades, DRAM advancement, and R&D. While its capacity ranks fourth globally, its 7.67% Q4 2025 market share lags behind leaders Samsung, SK Hynix, and Micron. Analysts note the company must now prove its ability to achieve stable mass production with high yields and low cost-per-bit, especially for advanced products. Its growth currently relies on transitioning from DDR4/LPDDR4X to DDR5/LPDDR5X and increasing domestic substitution. Successfully developing and commercializing high-value AI products like HBM is seen as crucial for future competitiveness and closing the gap with international giants.

marsbit44m ago

From a Loss of 19.2 Billion to a Profit of 7.1 Billion, ChangXin Technology States 'Downturn Cycle Remains a Concern'

marsbit44m ago

Stop Writing Prompts: Claude’s Official Guide to 4 Types of Loops That Automate Work

The article discusses a shift in AI development from manually crafting prompts to designing "loops"—systems where AI agents autonomously perform tasks until a defined stopping condition is triggered. Inspired by figures like Peter Steinberger and Boris Cherny, this approach, termed "loop engineering," focuses on creating self-running systems rather than one-off interactions. Claude Code's team formally defines a loop as an agent repeatedly executing work until a stop condition is met and categorizes four primary loop types based on their stopping mechanisms: 1. **Turn-based loops:** Human-controlled, step-by-step execution for short, discrete tasks. 2. **Goal loops (/goal):** An evaluator model checks outputs against predefined, quantifiable objectives (e.g., a performance score), forcing retries until the goal is met or a limit is reached. 3. **Time loops (/loop and /schedule):** Time-triggered, like cron jobs, for recurring tasks (e.g., daily summaries) or monitoring external systems. 4. **Proactive loops:** Event or time-triggered, fully automated workflows for ongoing, bounded tasks like bug triage, running until manually stopped. The core shift is from designing prompt content to designing the behavioral system—its triggers, verification mechanisms, and termination rules. Effective verification, where the agent can self-check its output, is highlighted as crucial for loop efficiency. The article warns that uncontrolled loops risk high costs and getting stuck in unproductive cycles. It recommends implementing essential "gates": machine-verifiable completion conditions, hard limits on iterations/cost, and stagnation detection. Best practices include using smaller models where possible, testing on small scales first, and automating deterministic parts with scripts. In summary, AI programming is evolving from prompt engineering to system design, where the skill lies in architecting loops that can autonomously execute, validate, and decisively conclude their work.

marsbit45m ago

Stop Writing Prompts: Claude’s Official Guide to 4 Types of Loops That Automate Work

marsbit45m ago

Trading

Spot
活动图片