Should RWA Issuers Freeze Stolen Assets Automatically?

August 18, 2026

On May 30, 2026, an attacker drained roughly $5.4 million from Gravity Bridge, a cross-chain bridge connecting Ethereum and Cosmos. The stolen assets went to 0x7B582033061b96cC3F9421e73a749ED7C62da1F9: about $4.3M in USDC, $434K in USDT, 274 WETH and 14.164 PAX Gold. PAXG is worth studying.

PAXG is a real-world asset. Each token is a claim on a specific allocated gold bar. Unlike ETH, it is freezable by design: the Paxos token contract carries an asset protection role that can freeze any address on chain and wipe the balance so the backing asset can be seized by the appropriate authority. The capability is not theoretical. In November 2022, Paxos froze 11,184 PAXG taken in the FTX drainer incident and later burned it.

So the tooling existed, and it worked. Forta flagged the exploit as it happened. The stolen assets then sat in the attacker's wallet, in public view, for 27 minutes before the attacker routed the PAXG through Uniswap and traded it into WETH in two transactions.

Twenty-seven minutes was the entire decision window. Once the swap cleared, the gold-backed claim had become an asset no issuer on earth can freeze.

That is almost certainly not enough time for a manual review, and in many cases the window will be shorter still. But it is enough time for an automated one. A freeze triggered by policy rather than by deliberation can land in seconds, and the human review then happens where it belongs: afterward, deciding whether the freeze holds, rather than deciding whether the freeze happens at all.

The exposure is no longer marginal

Tokenized real-world assets, excluding stablecoins, exceed $38 billion in onchain, up over 100% YoY. Every one of those instruments has an issuer with a legal obligation to the underlying asset, and most have a contract function that can stop a thief from moving it. What almost none of them have is a policy that can fire before the attacker moves the funds.

What issuers actually do today

Two operating models dominate, and both were built for a slower world.

Tether acts on credible intelligence, often within hours and often ahead of any formal order. It works with hundreds of law enforcement agencies, has blacklisted thousands of addresses and has frozen billions of dollars of USDT. It can burn frozen tokens and reissue clean ones to victims.

Circle has historically required a lawful order. The cost of that posture became public in April 2026, when a North Korea-linked group drained roughly $285 million from Drift Protocol. Circle was criticized for not freezing stolen USDC for more than six hours, while the funds moved during US business hours, partly across Circle's own bridging infrastructure. A class action followed. Drift moved its settlement stablecoin to a competitor.

Paxos sits closer to the second model by its own terms and conditions, which state that it freezes only on a formal legal directive from a regulator, court, or law enforcement agency or under pre-agreed contractual terms with a partner.

Regulation reinforces that instinct. The GENIUS Act made freeze capability a federal requirement for payment stablecoin issuers, and set the standard that is now spreading across the tokenized asset stack: hold the technical ability to seize, freeze, burn or block transfers, and comply when a court or agency issues a lawful order. It is a sound rule, and it settles whether the button should exist. What it does not settle is who presses it, on what evidence and how fast. An issuer reading only the statute would reasonably conclude that the trigger is meant to be external, documented, and after the fact.

What a defensible fast-freeze policy looks like

The objection to automatic freezing is real: a private company unilaterally locking user funds is a serious power. But "slow" is not the same as "careful." The answer to the risk of a wrong freeze is a designed process, not a delayed one.

Pre-authorized triggers. Define in advance the narrow set of conditions that warrant provisional action: confirmed protocol exploit, funds from an address flagged by multiple independent intelligence providers, known drainer patterns. The judgment happens once, when the policy is written, not while the clock is running.

Provisional and time-bounded. A freeze that expires in 72 hours unless affirmed by counsel or an order is a very different instrument from a permanent seizure. It buys the window without pre-judging the outcome.

A published appeal path. Reversibility is what makes speed legitimate, and the absence of a documented appeal mechanism is precisely what makes issuers reluctant to act quickly.

Sub-minute execution. The detection and automation tooling is mature. What is missing is the decision from the asset issuer to turn an alert into a freeze transaction without a human in the loop. 

Institutional allocators will start asking issuers what they are actually doing to react to these kinds of incidents. The RWA market is being built on the promise that tokenization brings institutional-grade assets onchain without institutional-grade risk being left behind. Right now, the average issuer's answer to an in-progress theft is a process built for a world where money moved at the speed of a wire transfer. The attackers already know that.

Share