Circle blacklisted the Ethereum smart contract address for Zama's Confidential USDC (cUSDC) wrapper at 01:08 UTC on May 30, 2026, freezing approximately $12.6 million in USDC. The action followed a temporary restraining order issued May 29 by U.S. District Judge P. Casey Pitts in the Northern Dis...
"Circle follows the rule of law, and we are able to undertake actions such as freezing a wallet at the direction of law enforcement or the courts." — Jeremy Allaire, CEO, Circle
Circle blacklisted the Ethereum smart contract address for Zama's Confidential USDC (cUSDC) wrapper at 01:08 UTC on May 30, 2026, freezing approximately $12.6 million in USDC. The action followed a temporary restraining order issued May 29 by U.S. District Judge P. Casey Pitts in the Northern District of California, tied to a civil lawsuit alleging treasury misappropriation at DeFi yield protocol Overnight Finance. Zama's native token fell 18% within hours.
The freeze is notable not for its dollar amount — Circle has blacklisted 372 addresses totaling roughly $110 million since USDC's launch — but for its mechanism. A single court order targeting one depositor's funds locked the entire contract, trapping every user who had deposited USDC into Zama's privacy wrapper. Zama received no advance notice. The incident exposes a structural fault line: privacy protocols built on centralized stablecoins inherit the issuer's compliance surface, and that surface now extends to contract-level blacklisting.
At 01:08 UTC on May 30, 2026, Circle added the Ethereum address of Zama's cUSDC contract to the USDC blacklist. The blacklist function, built into USDC's ERC-20 smart contract, prevents the address from sending or receiving tokens. Approximately $12.6 million in USDC held inside the contract became immovable.
The freeze was executed pursuant to a temporary restraining order (TRO) issued May 29 by Judge P. Casey Pitts in the U.S. District Court for the Northern District of California. The TRO directed Circle to blacklist assets linked to an alleged unauthorized transfer from Overnight Finance's treasury.
On-chain investigator ZachXBT flagged the blacklist action publicly on May 30, identifying the specific deposit flow that triggered the legal action.
Within hours, Zama's native token (ZAMA) dropped from approximately $0.0389 to $0.0318 — a decline of 18.28% over roughly five and a half hours of trading. Zama subsequently paused its cUSDC, cUSDT, and cWETH wrapper contracts and retained U.S. legal counsel.
The freeze traces to a civil dispute at Overnight Finance, a DeFi yield protocol. According to court filings cited by The Block, the plaintiff — Newton AC/DC Fund LP — alleges that Maxim Ermilov misappropriated more than $15 million from Overnight Finance's treasury.
The sequence of events, according to on-chain analysis and court documents:
The wallet that made the deposit showed no sanctions flags and no KYT (Know Your Transaction) alerts at the time of deposit, according to Zama. The address had, however, participated in Overnight Finance governance voting — a detail ZachXBT flagged as connecting it to the disputed treasury operations.
Zama is a privacy infrastructure protocol built on fully homomorphic encryption (FHE). Unlike zero-knowledge proofs, which prove a statement without revealing underlying data, FHE allows computation on encrypted data without decrypting it. Zama's fhEVM — the Fully Homomorphic Encryption Ethereum Virtual Machine — enables smart contracts where state variables remain encrypted.
The cUSDC wrapper converts standard USDC into a confidential ERC-7984 token. Users deposit USDC into the contract and receive cUSDC with encrypted balances and transfer amounts. On a block explorer, transactions appear as opaque encrypted blobs rather than readable addresses and values.
The design includes compliance controls: authorized parties can decrypt their own data or provide compliance proofs as needed. However, the contract itself holds all deposited USDC at a single Ethereum address — the one Circle blacklisted.
This architecture creates a single point of failure. Blacklisting the contract address freezes every USDC unit inside it, regardless of the depositor's identity or compliance status.
The core issue is proportionality. The TRO targeted funds allegedly linked to one individual's alleged misappropriation. The blacklist affected every user of the cUSDC contract.
According to reporting from The Block and CryptoTimes, the single deposit from the Overnight Finance-linked wallet constituted more than 99% of the cUSDC contract's balance. This meant the collateral damage to other users was, in dollar terms, limited to roughly 1% of the frozen amount — perhaps $126,000 or less.
However, the precedent is broader than this specific case. Any privacy wrapper, mixer, or pooled contract that holds centralized stablecoins faces the same risk. A single tainted deposit of sufficient size gives a court actionable grounds to freeze the entire pool.
Rand Hindi, Zama's co-founder and CEO, stated: "This has nothing to do with Zama, or privacy." He described the protocol as "caught in a crossfire." Zama's team said it was not notified before the blacklist was executed and is working to isolate the flagged deposit so unconnected users can regain access.
Circle has blacklisted approximately 372 USDC addresses since the token's launch, freezing roughly $110 million in aggregate, according to on-chain data compiled by multiple analysts.
In March 2026, a private law firm obtained a court order requiring Circle to freeze 16 business wallets simultaneously. The frozen addresses included crypto exchanges, online casinos, forex brokers, payment processors, and the ckETH Minter smart contract — a bridge operated by the DFINITY Foundation. That incident similarly froze a shared infrastructure contract.
Circle CEO Jeremy Allaire articulated the company's policy in an April 13, 2026 press conference in Seoul: Circle does not freeze wallets unilaterally. It requires "a formal legal basis" — a court order, law enforcement directive, or sanctions designation. Allaire described the alternative as a "moral quandary," arguing that a private company should not decide independently which assets to freeze.
This policy was tested during the Drift Protocol hack in early 2026, where approximately $230 million in USDC was moved across chains over several hours. Circle did not freeze the funds because no court order was in place. ZachXBT estimated that Circle's policy of waiting for legal process has allowed over $420 million in illicit funds to escape since 2022.
The tension is structural: acting too fast risks freezing innocent users (as in the Zama case); acting too slowly allows stolen funds to move beyond reach.
Tether operates under a different enforcement model. As of May 2026, Tether has blacklisted over 7,200 wallet addresses and frozen $4.2 billion in tokens — roughly 38 times Circle's frozen total. Tether cooperates with over 310 law enforcement agencies across 62 jurisdictions, assisting in more than 1,800 active investigations, according to company disclosures.
In a single action on April 23, 2026, Tether froze $344 million in USDT across two addresses, acting on information from the Office of Foreign Assets Control (OFAC) and U.S. law enforcement.
| Metric | Circle (USDC) | Tether (USDT) | |--------|--------------|---------------| | Total blacklisted addresses | ~372 | ~7,200+ | | Total frozen value | ~$110M | ~$4.2B | | Freeze trigger | Court orders only | Law enforcement requests, proactive | | Recent 30-day freeze volume | Not disclosed | ~$515M |
The difference reflects both scale (USDT's circulating supply is larger) and philosophy. Tether acts proactively, often freezing wallets at law enforcement's request before formal court proceedings conclude. Circle waits for judicial authorization.
Both approaches carry costs. Tether's proactive model freezes more funds faster but raises due process concerns. Circle's court-order model provides legal certainty but creates windows for fund movement.
The GENIUS Act, enacted in 2025 and now in its implementation phase, codifies stablecoin issuers' obligation to maintain freeze capabilities. Under the Act, all payment stablecoin issuers — including foreign issuers operating in U.S. markets — must maintain the technical capability to "promptly comply with any court order or government directive to freeze, block, or burn stablecoins."
The Act further requires issuers to maintain "policies and procedures to block, freeze, and reject specific or impermissible transactions that violate Federal or State laws." The OCC issued a Notice of Proposed Rulemaking in 2026 to implement these provisions.
Circle has advocated for a "safe harbor" provision within the CLARITY Act that would shield issuers from liability when taking preventive freeze actions under extreme circumstances, according to Allaire's April 2026 statements. As of May 31, the CLARITY Act has cleared the Senate Banking Committee with a 15-9 vote but has not reached the Senate floor.
The legislative trajectory is clear: freeze authority is not a bug in the stablecoin system. It is a feature, mandated by law.
The Zama freeze crystallizes a design problem for privacy protocols that accept centralized stablecoins.
Pooled contracts are vulnerable. Any wrapper, mixer, or confidential token contract that pools centralized stablecoins at a single address creates a contract-level freeze surface. One tainted deposit of meaningful size can trigger a freeze that affects all depositors.
FHE does not protect against issuer-level controls. Zama's homomorphic encryption conceals balances and transaction amounts from on-chain observers. It does not and cannot conceal the contract address itself from the issuer. The encryption operates at the application layer; the freeze operates at the token layer.
Privacy and compliance are not inherently opposed, but the current architecture forces a binary outcome. Either the entire contract is frozen or it is not. There is no mechanism for Circle to freeze a specific depositor's encrypted balance within the cUSDC contract without Zama's cooperation to decrypt and isolate the relevant funds.
Zama has stated it will work to isolate the flagged deposit. If it succeeds, the model becomes: privacy protocol cooperates with issuer post-freeze to separate tainted from clean funds. This is closer to how traditional financial institutions handle asset freezes — targeted, not blanket — but it requires the privacy protocol to act as a cooperative intermediary.
The alternative is building privacy wrappers exclusively around decentralized stablecoins (DAI, LUSD, or similar) that lack issuer-controlled blacklist functions. This trades freeze risk for liquidity constraints, since centralized stablecoins dominate the market.
The Zama freeze is a $12.6 million case study in the limits of on-chain privacy built on centralized infrastructure. Fully homomorphic encryption can hide what users do with their tokens. It cannot prevent the token issuer from rendering those tokens immovable.
Circle acted within established legal process. Judge Pitts issued a TRO; Circle complied. The mechanism worked as designed — which is precisely the problem for users who believed encryption provided protection against exactly this kind of intervention.
The stablecoin market, now exceeding $323 billion in total supply, is moving toward greater, not lesser, issuer control. The GENIUS Act requires it. Courts are using it. Privacy protocols that do not account for this in their architecture will face recurring episodes of collateral damage.
The question is no longer whether stablecoin issuers can freeze privacy contracts. They can. The question is whether privacy protocols can architect around this reality while remaining useful — or whether confidential stablecoins built on centralized tokens are a contradiction in terms.