Stolen XRP keeps moving on the XRP Ledger because the protocol has no freeze or clawback for its native asset. Unlike stablecoins, XRP has no issuer who can block or recover funds, which brings unique risks for users and exchanges.
When $83 million in XRP was stolen during the Bitget security breach, investigators could watch the funds move across the XRP Ledger in real time. But no one could freeze or claw back the stolen coins at the protocol level. Native XRP runs on rules that are different from most tokens or stablecoins. There is no way for an issuer to step in, even after a major theft.
Freeze controls and their limits
Stablecoins like USDT or USDC are issued by companies that can freeze or claw back tokens. Native XRP is different. It has no issuer and no admin controls. The XRP Ledger protocol does not let Ripple, validators, or anyone else freeze, blacklist, or recover XRP from a user's self-custody address. This difference was clear during the Bitget hack. Stolen XRP kept moving between addresses, while stablecoins tied to the hack were frozen by their issuers.
No one can freeze XRP in the XRP Ledger; freeze and clawback mechanisms are strictly limited to issued tokens, not the native asset.
Centralized exchanges can still block access to XRP they hold for users. If law enforcement or compliance teams spot stolen funds at an exchange, the platform can freeze the user's account and stop withdrawals. But this is off-chain. It's an account-level block, not a protocol freeze. Once XRP leaves an exchange and goes to a self-custody wallet, it is out of reach for any admin or issuer.
XRP Ledger asset types
The XRP Ledger supports several asset types, each with its own controls. Native XRP is tracked as part of an account's balance. It cannot be frozen or clawed back. Tokens issued on the XRP Ledger-like stablecoins or other assets-use trust lines and can have issuer-level controls. Issuers can set up these tokens to allow freezing, locking, or even clawback, depending on how the asset is built and what the issuer wants.
Newer Multi-Purpose Tokens (MPTs) on the XRP Ledger also support issuer controls, including optional locking and clawback. But these features only work for issued tokens, not for native XRP. The protocol's documentation is clear: no one can freeze or recover XRP itself.
The XRP Ledger distinguishes sharply between native XRP and issued tokens: freeze, clawback, and global freeze controls are available only for issued assets, not for XRP itself. This separation is fundamental to the protocol's design and is detailed in official documentation.
Security incidents and recovery
The Bitget breach in September 2026 showed what these design choices mean in practice. Blockchain watchers could see where the stolen XRP was, but they could not stop it from moving. Stablecoin issuers like Circle and Tether reportedly froze $320,000 in related funds by targeting specific Ethereum addresses. For XRP, recovery depends on tracing the funds to a centralized exchange or service provider willing and able to act at the account level.
Validators on the XRP Ledger cannot freeze accounts or reverse transactions. Their job is to take part in the consensus process that decides which transactions go into the ledger. The protocol can change through amendments if more than 80% of trusted validators agree for two weeks. But under current rules, there is no way to freeze native XRP.
Issuer control and user risk
The fact that native XRP cannot be frozen or clawed back is not a bug. It comes from the asset's design. With no issuer, there is no central authority to enforce blocks or recover funds. This makes XRP different from tokens that represent claims on outside assets or are managed by known entities. For users, this means self-custody of XRP brings both freedom and risk. Once funds are sent to another address, there is no protocol-level way to get them back if they are lost or stolen.
Centralized exchanges are the only real chokepoint for intervention. If stolen XRP lands in an exchange account, the platform can freeze access to those funds. But if the coins stay in self-custody wallets, recovery is limited to tracking and reporting, not technical enforcement.
Official XRP Ledger documentation says the total supply of XRP was set at 100 billion when the network started. No more XRP can be created. Every transaction destroys a small amount of XRP as a fee, slowly reducing the total supply. This supply rule is separate from freeze controls but shows the protocol's focus on fixed, issuerless rules.
For U.S. users and exchanges, the difference between native XRP and issued tokens is not just technical. It shapes how security incidents, compliance, and user protections work in real life. Knowing who controls an asset, and at what layer, is key for judging custody risk and recovery options.
After the Bitget incident, the XRP Ledger's design means native XRP stays outside the reach of issuer-level freezes, even as other assets on the same network can be locked or clawed back by their creators. This design brings transparency and finality, but it also means that mistakes and thefts involving XRP are often permanent at the protocol level.
On September 26, 2026, blockchain data showed the attacker had moved about $83 million in stolen XRP, with another $75 million still in original addresses. At the same time, stablecoin issuers froze $320,000 in related funds. The XRP Ledger's fixed supply of 100 billion XRP has not changed since it was created, and every transaction still burns a small amount of XRP as a fee, cutting the total supply over time.
Unlike many tokens, native XRP's lack of an issuer means users must rely on their own security and, sometimes, on centralized exchanges to recover lost or stolen funds. This trade-off between control and recoverability is a core part of the XRP Ledger's design.