Blog
7 min readPublished October 28, 2026

Stolen USDT Landed on an Exchange: How to Request a VASP Freeze

When stolen USDT hits a CEX deposit, open a support ticket with a consistent packet and push LE onto LERS—venues generally cannot unilaterally freeze another user without lawful process.

Wallet Operations
Sanctions & Wallet Screening
Stablecoins & Freezeable Assets
#wallet-screening
#USDT
#law-enforcement
#Tether
#freeze-risk
#compliance
Stolen USDT Landed on an Exchange: How to Request a VASP Freeze

When stolen USDT lands in an exchange deposit address, the workable ask is a VASP freeze / preservation path - not a retail “paste the TxID and claw it back” button. Victims and desks open a support ticket with a consistent evidence packet, file a local police / cybercrime report the same day, and push law enforcement onto the venue’s official Law Enforcement Request System (LERS). Most major exchanges, including Binance in its public FAQ, state they cannot unilaterally freeze another user’s assets without an appropriate official freezing order from competent law enforcement or a court. Parallel issuer blacklisting is a separate plane; it does not replace the VASP track when funds sit on custodial rails.

Educational only. Not legal advice. Not a recovery service. FreezeRadar does not file freeze requests, does not impersonate law enforcement, and does not help evade freezes. Anyone DMing an “FBI recovery desk” or asking for seed phrases / upfront crypto “fees” is running a second scam.

Handshake / commercial desk metaphor for requesting a VASP freeze after stolen USDT lands on an exchange.

Check a wallet before you act

Run a FreezeRadar scan for issuer-freeze signals, sanctions exposure, counterparty risk, and freezeable asset sensitivity before moving funds.

Scan a wallet

Direct answer

Report stolen funds to Binance (or any VASP) as a two-channel problem: (1) victim/support ticket with hashes, explorer links, and a police report copy; (2) an authorized LE agent submitting through the venue’s LERS / Kodex portal (or equivalent) with valid process. Binance’s own FAQ on stolen funds transferred to Binance is explicit: gather incident narrative, ownership proof screenshots, compromised wallet details, full TxID list with clickable explorer URLs, and a police report - and understand that Customer Support cannot unilaterally freeze the receiving user’s balance. Ask your case officer to use the published LE intake. Do not invent SLA clocks; turnaround depends on jurisdiction, process quality, and whether funds remain credited.

Reuse the field list in Stolen USDT freeze-request evidence packet. This article owns the exchange-channel fork of that packet - not a rewrite of the packet itself.

What this is (and is not)

SituationRight planeWrong plane
Your own CEX account is held for KYC / AML / LEVenue account taxonomyIssuer isBlackListed
Stolen USDT deposited into someone else’s CEX hot walletVASP freeze + LE portalRetail support “refund” fantasy
Stolen USDT still on EOAs / mixers / bridgesIssuer + LE; then VASP if it hits a depositAssuming the CEX can reverse a confirmed hop that never credited
Your withdrawal is stuck pending reviewExchange hold vs issuer blacklistFiling a stolen-funds LERS as if you were the victim of an external drain

If the wallet itself shows an issuer freeze, triage with issuer blacklist vs exchange hold and documents for frozen stablecoin wallet review. Those guides explain your credited balance. This post is the outbound ask when thieves deposited into a venue.

Channel map: support ticket vs LERS

A. Victim / desk support ticket (you can open this)

Purpose: put the venue on notice with a clean hash trail so fraud/security can correlate deposits while LE process catches up.

Minimum attachments (same story every time):

  1. Incident narrative (UTC + local timestamps labeled).
  2. Victim source address(es); destination deposit address(es); intermediate hops.
  3. Full TxID list with clickable explorer links (not bare hashes in a chat).
  4. Screenshots that support wallet ownership (login flow, device, prior funded activity) - never a seed phrase.
  5. Police / cybercrime report number or acknowledgement PDF.
  6. One-paragraph ask: preserve logs; evaluate hold on specific credited deposits pending lawful process; coordinate with named case agent.

Binance’s public FAQ lists essentially this set. Other VASPs publish analogous “report stolen crypto” forms; the fields rhyme even when the UI differs. Keep glossary: stolen funds language consistent across tickets.

B. Law-enforcement portal (only authorized agents)

Purpose: the channel that can actually carry a freeze / preservation / disclosure order.

For Binance, the published Government Law Enforcement Request System (LERS) routes through Kodex (app.kodexglobal.com/binance/signup for global LE; a separate China endpoint exists). Official guidance: government email, valid legal process documents, background summary, identifiers (TxIDs, UIDs, addresses). Exigent flags exist for life-threat / terrorism / child-exploitation categories the venue defines - do not invent “exigent” for ordinary theft. Agency verification via VPN is commonly rejected.

Victim reality check: you cannot register as LE. Your job is to get a local report filed fast enough that an investigator can use LERS. Customer Support will usually refuse to share confidential LE correspondence with you; ask the case officer for status.

C. What venues typically cannot do unilaterally

Public Binance language is representative of large VASPs: without an appropriate official freezing order from LE or a competent court, they are unable to unilaterally freeze another user’s assets. Informal “we emailed support” is notice, not a freeze. Do not coach customers to structure withdrawals to dodge holds - document and escalate lawfully only. Broader contact routing lives in contact issuer / exchange / LE.

Parallel issuer request (do not skip when balances remain on-chain)

If residual USDT still sits on EOAs that show transferable balances, open the issuer plane in parallel - after LE intake is started - using the same packet. Tether’s Token Terms and Law Enforcement Requests policy describe blacklisting / freezing under prohibited-use and lawful-process frames; Circle’s USDC terms reserve freeze / block-list tools under compliance responses. Neither is a retail “unsteal” portal. See the evidence-packet post for field reuse; this article does not re-list every exhibit.

When funds have already fully credited and been traded off a CEX, issuer blacklist on the deposit address may still matter for residual hops - but the first-hour priority is usually the VASP while credits sit.

Desk triage script (first 90 minutes)

  1. Confirm the hop. Explorer: theft tx → first exchange-tagged deposit. Screenshot + save HTML.
  2. Read freeze planes. Victim address isBlackListed / getBlackListStatus (timestamp). Deposit address status. Do not confuse a venue credit hold with issuer blacklist.
  3. Open support ticket with the minimum packet above. One folder; identical narrative.
  4. File LE / cybercrime in the victim’s jurisdiction the same day (IC3 for U.S. persons when applicable - ic3.gov; local cybercrime portals elsewhere).
  5. Hand the LERS URL and FAQ to the case officer; do not claim you submitted as LE.
  6. Quarantine desk flow. Stop settling against contaminated addresses; rotate receive wallets; revoke stray allowances if the drain was approval-based.
  7. Refuse recovery DMs. Upfront “unfreeze fee” in crypto is a second theft.

Worked composite (not a case file)

OTC desk customer reports 180k USDT TRC-20 drained after a fake “deposit verification” approve. Tronscan shows two EOA hops, then a labeled Binance deposit cluster. Victim isBlackListed=false. Desk actions same afternoon: Binance security ticket with clickable Tronscan TxIDs + ownership screenshots + local cybercrime acknowledgement; customer files IC3/local report; case officer pointed at Binance LERS/Kodex; issuer channel only for any residual EOA balances counsel/LE support; revoke remaining approvals; new receive address for future settles. Wrong path: Telegram “Tether insider” asking 12% upfront, or waiting a week hoping support “just reverses it.”

Limitations (read before you file)

FreezeRadar scans and explainers show issuer blacklist / sanctions-adjacent signals and desk workflows. They cannot prove a CEX will freeze a credited deposit, cannot see sealed LE process, and cannot invent SLA times. April 2025 onward reporting on some venues’ MLAT / foreign-routing policies for non-exigent LE requests is secondary journalism - treat it as context that process quality and jurisdiction matter, not as a promise that any specific ticket will be fast or slow. Outcomes depend on whether funds remain, whether lawful process issues, and venue policy - not on paste-a-hash tools.

Key takeaway

Stolen USDT on an exchange is a support ticket + LE portal problem. Build one packet, open notice with the VASP, get a case number, push authorized agents onto LERS, and run issuer requests in parallel only where freezeable on-chain balances remain. No private recovery firm replaces that stack.

Next steps: assemble the evidence packet, follow contact issuer / exchange / LE, screen staging wallets on FreezeRadar, and keep exchange hold vs issuer blacklist bookmarked so you do not mis-file the plane.

References

  1. Binance Support - How to Report Stolen Funds Transferred to Binance - https://www.binance.com/en/support/faq/detail/360000006051
  2. Binance Support - Government Law Enforcement Request System (LERS) - https://www.binance.com/en/support/law-enforcement
  3. Binance Support - Law Enforcement Guidelines - https://www.binance.com/en/support/law-enforcement/guidelines
  4. FBI Internet Crime Complaint Center (IC3) - https://www.ic3.gov/
  5. Tether - Legal / Law Enforcement Requests - https://tether.to/en/legal/?tab=law-enforcement-requests
  6. Circle - USDC Terms - https://www.circle.com/legal/usdc-terms
Sources (6)

Continue exploring FreezeRadar knowledge content.