On-chain investigator ZachXBT has published a new report, titled “The Circle USDC Files,” alleging more than $420 million in compliance failures tied to the company’s USDC stablecoin since 2022.
The analysis, released on social media platform X on Friday, chronicles multiple high‑profile decentralized finance (DeFi) exploits in which Circle allegedly failed to use its on‑chain freezing and blacklist capabilities to halt the flow of stolen funds.
Alleged Inaction By CircleCircle’s token contract includes an explicit freeze/blacklist function, and the company’s terms of service reserve the right to restrict access for suspected illicit actors “in its sole discretion.”
The report opens with the April 1, 2026, Drift Protocol exploit, in which the attacker drained roughly $280 million. According to ZachXBT, the thief used Circle’s Cross‑Chain Transfer Protocol (CCTP) to bridge more than 232 million USDC from Solana (SOL) to Ethereum (ETH) in over 100 transactions.
Nine‑Figure Losses In Crypto HacksLaw enforcement requested freezes from four stablecoin issuers — Circle, Tether, Paxos, and Techteryx — for two addresses tied to that investigation. The report claims the other three issuers acted quickly, while Circle took approximately 4.5 months longer to freeze the same addresses.
Taken together, ZachXBT says these cases — many of them public and high‑value — add up to nine‑figure losses to the crypto ecosystem caused by repeated inaction over a multi‑year period.
“They have every tool and resource available to do better. They just haven’t,” he writes, closing his report with a pointed question: who, exactly, is Circle serving?
Featured image from OpenArt, chart from TradingView.com


















