In September 2026, a hacker exploited Bitget, one of the major centralized cryptocurrency exchanges, and made off with approximately $83 million in stolen assets — including a significant amount in XRP. Within hours, Circle froze the USDC portion of the stolen funds. Tether froze the USDT portion. The stablecoins became worthless to the hacker: the issuers had effectively canceled them.
The XRP could not be frozen. Approximately $75 million in stolen XRP moved through multiple wallets on the XRP Ledger in the days following the hack, and Ripple — the company most closely associated with XRP's development — had no mechanism to freeze it. The XRP Ledger's architecture does not give any central party the unilateral ability to freeze native XRP. The hacker's funds moved freely.
The divergence between what happened to the stablecoins and what happened to the XRP illustrates the most important governance question for tokenized securities: can the issuer freeze or clawback tokens from a bad actor — and what does the architecture need to support that?
Why Freeze and Clawback Are Non-Negotiable for Institutions
Every regulated securities market in the world has a mechanism for reversing unauthorized transactions. When securities are stolen through broker fraud, court orders can compel custodians to return them. When a transfer agent makes an error, it can be reversed. DTCC has procedures for unwinding erroneous trades. The existence of a legal and operational mechanism for reversing bad transactions is a foundational feature of regulated markets — not a bug of centralization, but a requirement of investor protection.
For tokenized securities specifically, the regulatory requirement is explicit. The SEC's existing rules for securities transfers require that issuers and transfer agents have the ability to reject unauthorized transfers, reverse fraudulent ones, and comply with court orders compelling asset return. Any tokenization architecture that removes this capability is not compliant with existing securities law for US-registered securities, regardless of how the token standard is designed.
This is precisely why compliant institutional tokenization platforms include freeze and clawback functions. The ERC-1400 token standard includes forced transfer capability. ERC-3643's T-REX architecture includes issuer-controlled freeze functions. Securitize's platform — which manages BUIDL and other institutional tokenized funds — maintains administrative controls that allow the transfer agent to freeze tokens or reverse transfers in response to legal orders.
| Asset | In Bitget Hack | Frozen? | Why |
|---|---|---|---|
| USDC | Part of stolen funds | ✅ Frozen | Circle controls freeze function in USDC contract |
| USDT | Part of stolen funds | ✅ Frozen | Tether controls freeze function in USDT contract |
| XRP (~$75M) | Moved freely post-hack | ❌ Not frozen | XRP Ledger has no central freeze authority for native XRP |
The Architecture Choices That Determine Freezability
Not all tokens are created equal in their freezability. The key architectural variable is whether the token contract includes a centrally-controlled pause or freeze function, and whether a designated party (the issuer, transfer agent, or regulator) holds the cryptographic keys that control it.
Freezable: Most institutional tokenized securities platforms — BUIDL, tokenized Treasury products on Securitize, ERC-1400 or ERC-3643 based security tokens. The freeze function is built into the contract and controlled by the issuer or transfer agent.
Not directly freezable: Native layer-1 tokens where no central party controls the ledger — native XRP on XRP Ledger, native ETH on Ethereum, native BTC on Bitcoin. These can be frozen at the exchange level (centralized exchanges can block accounts) but not at the ledger level.
Partially freezable: Wrapped or custodied versions of non-freezable assets — WBTC (wrapped Bitcoin), for example, can be frozen at the custodian level because the custodian holds the underlying Bitcoin. The token's freezability depends on whether an intermediary holds the underlying asset.
The Lesson for RWA Issuers
The Bitget hack is a stress test that illustrates why institutional investors and regulators will insist on freeze and clawback capability for any tokenized asset that aspires to function as a regulated security. The question for RWA platform designers is not whether to include these capabilities — regulated securities require them — but how to implement them in a way that preserves as much of the benefits of blockchain (transparency, 24/7 settlement, composability) as possible while meeting the investor protection requirements that make the tokens institutionally acceptable.
The TSV framework's requirement that tokens convey "the same economic interest, dividends, voting, and liquidation rights as traditional shares of the equivalent class" implicitly includes the investor protection mechanisms that traditional shares have — including the legal infrastructure for reversing fraudulent transfers. A token that is more anonymous and less reversible than a traditional share is not conveying the same rights; it is conveying fewer of them.
→ RWA Token Standards — ERC-1400 and ERC-3643 freeze functions explained
→ What You Actually Own — rights comparison across token types
→ RWA Due Diligence Framework — smart contract audit is step one