Hacken found $91.3 billion of USDT on Tron sits behind a 2-of-3 multisig vulnerable to a two-key compromise, even as Bluechip upgraded Tether to C.
Hacken found $91.3 billion of USDT on Tron sits behind a 2-of-3 multisig vulnerable to a two-key compromise, even as Bluechip upgraded Tether to C.

Roughly $91.3 billion of USDT on Tron — half of all circulating supply — sits behind a 2-of-3 multisig contract that two compromised keys could seize, with no timelock or reversal mechanism, Hacken found.
"The multisig does not hold user funds — it controls the USDT contract itself, the power to mint tokens, freeze addresses and reassign ownership," Seher Saylık, a smart contract auditor at Hacken, told CoinDesk. "There is no built-in delay, cancellation process, or reliable way to undo the changes."
Hacken scored USDT 3.3 out of 10 on cybersecurity, even as rating firm Bluechip raised Tether's corporate grade to C from D after a KPMG US audit found reserves exceeded liabilities by $6.8 billion as of Dec. 31, 2025. The review found no evidence of compromised keys or a security incident. Tether reuses the same six signing keys across Ethereum, Avalanche and Celo, meaning a compromise on one chain could authorize administrative transactions on another.
USDT — a stablecoin pegged to the U.S. dollar — is crypto's primary liquidity layer with about $184.6 billion in outstanding supply. A two-key compromise would let an attacker change the contract owner, lock out Tether's legitimate signers, mint unlimited tokens and freeze or redirect balances, permanently stripping the issuer of its ability to freeze funds in law enforcement cases.
Saylık said an attacker could first reassign contract ownership to an address they control, then mint USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose transfer fees or redirect token balances. The attacker would not need access to individual users' wallets.
"The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not," said Leo Fan, founder and CEO of Cysic.xyz and former lead on quantum resilience at Algorand. "Half the supply, about $91 billion on Tron, still sits behind two keys with no timelock and nothing onchain seems to impede what those keys can mint tomorrow."
Bluechip's upgraded grade is the first to apply its expanded SMIDGE methodology, which incorporates Hacken's technical-risk analysis alongside a financial and governance review. The approach combines an assessment of an issuer's reserves with an examination of the code and administrative controls governing stablecoin issuance.
"Stablecoin ratings have always covered the financial side," said Benjamin Levit, CEO of Bluechip. "With Hacken's technical data now integrated into our methodology, we can finally rate the full picture."
Bluechip had kept USDT at its D rating for years. The KPMG audit addressed one of the conditions Bluechip had previously set for an upgrade: a full-scope audit of Tether's consolidated financial statements by an independent auditor.
Hacken said it has not yet completed a comparable assessment of Circle's USDC. Bluechip's B+ rating for USDC cannot be treated as a direct technical comparison because it was assigned under the earlier methodology, before Hacken's cybersecurity factor was introduced.
The findings echo risks that have hit other stablecoin issuers. Resolv's stablecoin fell 70 percent in March after an attacker minted tokens and extracted $25 million in ETH, and StablR disclosed unauthorized issuance of USDR and EURR following a security breach in May.
While Hacken confirmed Tether's off-chain financial backing, it noted no link between reserves and code execution: USDT's smart contracts have no automated proof-of-reserve checks and no cap on token creation, meaning once signers authorize a transaction, the contract will mint any amount without requiring proof of bank deposits.
S&P Global Ratings downgraded USDT to the weakest possible score on its stablecoin stability scale in November, citing concerns about its ability to maintain its dollar peg and gaps in reserve disclosure. Tether disagreed strongly, saying the rating agency applied a legacy framework that does not capture the nature of digitally native money.
This article is for informational purposes only and does not constitute investment advice.