Three distinct incidents—unsolicited dust transfers sent from wallets linked to HTX to exchange hot wallets, the theft of approximately $388 million from Bitget through forged internal instructions, and the U.S. Senate's scrutiny of Iran-related USDT fund flows—together reveal one fact: control over a crypto wallet is not held solely by the private key holder, but is distributed among senders, custodians, issuers, and regulators.
One exchange received an asset it never asked for; another exchange sent out an asset it never authorized; and holders of a third asset may find their tokens frozen even while holding the wallet's private key. So-called "crypto wallet control" depends on who exactly wants to put money in, take money out, or stop it from moving.
Transfers No One Asked to Receive
In August of this year, a batch of wallets identified as being linked to HTX sent small transfers to receiving addresses belonging to other exchanges. Kraken said that after receiving such funds, some customer accounts on its platform were briefly restricted. But multiple exchange insiders revealed that the broader problem affected hot wallets at multiple exchanges across the industry: affected operators were temporarily unable to transfer funds out of these wallets while compliance teams assessed the risk exposure.
People familiar with the matter believe this pattern was deliberate. It is currently impossible to independently confirm the exact number of affected exchanges, nor to confirm who orchestrated these transfers. HTX has denied initiating these transfers and questioned the accuracy of attributing these sending wallets to it.
The amounts were tiny, but the operational impact was not. Exchange hot wallets may manage substantial funds, but operators cannot refuse incoming transfers to their public addresses. If a transfer deemed to come from a sanctioned source prompts an exchange to suspend outbound withdrawals until it can isolate or assess the funds, then the sender can create chaos at extremely low cost. The arrival of funds only proves that a transfer occurred; it does not prove that the exchange wishes to establish any relationship with the sender.
This is precisely one boundary of crypto wallet control: operators can guard their private keys and set withdrawal rules, but an address remains open to funds it never requested. And its compliance response then determines whether the rest of that wallet can continue to be used.
"Legitimate" Transfers Based on Forged Instructions
At Bitget, assets flowed in the opposite direction. According to the exchange's account of the September security incident, attackers exploited a vulnerability in a third-party security product, obtained high-privilege internal credentials, and injected forged withdrawal instructions into its wallet system. Bitget stated that its private keys were not stolen, but its hot and warm wallets still executed unauthorized transfers, with estimated losses currently around $388 million. An independent forensic investigation is still ongoing.
On-chain, these transfers were valid—but that has nothing to do with whether the exchange was willing to execute them. Allegedly, the attackers compromised the process that "tells the wallet what to sign," bypassing risk controls before normal withdrawal records were generated.
This also shows that a customer's self-maintained "approved withdrawal address list" is not the point. The reported attack targeted the exchange's wallet infrastructure, not a customer selecting a receiving address within their account. When a signer accepts an instruction simply because it appears to come from a trusted internal system, it can faithfully execute an instruction whose authority has been forged.
Bitget is currently tracking the stolen assets and working with others to freeze a portion of them. Freezing funds works here; in the dust transfer incident, the suspension triggered by the exchange's own compliance controls was itself part of the disruption. These two mechanisms are fundamentally different and have opposite effects on the affected operators.
A Digital Dollar That Can Be Stopped
The Iran-related USDT case introduces a third role with power over a wallet: the issuer of the asset within the wallet. A USDT holder can control the private key of an address, but Tether can prevent that address from transferring tokens out. The wallet still exists, but the assets within it cannot be used.
A report by Democratic staff of the U.S. Senate Permanent Subcommittee on Investigations traced USDT flows between wallets it identified as linked to Iran's central bank and intermediary networks, and questioned whether Tether identified and froze Iran-related wallets quickly enough. Tether stated that in 2026 it cooperated with U.S. authorities to freeze approximately $550 million in Iran-related USDT. The report is a minority staff investigation and does not constitute a finding that Tether violated the law.
Iran-related actors are seeking ways to continue transacting despite limited access to international banking services. Whether these restrictions are justified is a separate political and legal question. For the purposes of this article, the truly noteworthy fact is this: a digital dollar can flow across borders without any bank willing to cooperate, yet its issuer retains the ability to stop it at specific addresses.
For those moving funds and those tracking them, this combination is more useful than physical dollars. Cash changes hands between people without leaving a public record, and no issuer can remotely freeze a particular banknote; bank transfers leave records, but those records are scattered within individual institutions and inaccessible to the public. On-chain USDT transfers leave a visible trail: investigators can trace it, and Tether can freeze USDT at identified addresses. The speed of fund movement and the possibility of intervention come from the same digital design.
Opaque fund flows did not begin with the crypto industry either. The 1992 U.S. Senate investigation into BCCI found that the CIA continued to use the bank and its secretly held U.S. subsidiary, First American, for operations even after learning of the bank's misconduct. Traditional finance has long provided pathways that outsiders—sometimes even regulators—find difficult to see clearly.
Blockchain visibility also has its boundaries. It shows transfers between addresses, not who is behind each address, nor the payments made to purchase those tokens. The Senate report relied on documents, sanctions lists, and fund tracing to map some wallets to people and institutions. Tether's freeze power is only useful when there is enough information to determine where to act.
Control Is Not in Just One Place
These three cases reveal different powers surrounding the same basic object: a sender can push assets into a wallet whose operator has no desire to participate in the transaction; a compromised internal system can cause an exchange to transfer assets out; and a token issuer can prevent assets within a wallet from moving even when the holder wishes to trade.
The ability to "stop funds" is a vulnerability when small unsolicited transfers disrupt an exchange, a remedy when stolen funds are frozen, and a tool of sanctions enforcement when USDT is blocked. An exchange's operational suspension and an issuer's token blacklist are not technically the same, and their impact depends on who has the authority to trigger them, on what evidence, and what remedies affected holders can obtain.
This is precisely the hardest question behind crypto wallet control. The chain records what moved and what stopped; but the power to decide whether it "should move" is shared among senders, custodians, issuers, and regulatory authorities—and the person most deeply affected does not always have the final say.






