Loading prices…
🩸BEARISH

USDT on Tron: Two Keys Could Control $91B, Audit Finds

The Hacken finding lands on the same day Tether's corporate grade rose on a Big Four reserves audit. The financial side now has a clean opinion; the on-chain side still doesn't.

USDT on Tron: Two Keys Could Control $91B, Audit Finds
USDT on Tron: Two Keys Could Control $91B, Audit Finds
USDT on Tron: Two Keys Could Control $91B, Audit Finds
USDT on Tron: Two Keys Could Control $91B, Audit Finds

About $91.3 billion of USDT on Tron, roughly half of all circulating supply, is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, with no built-in delay, cancellation window, or way to reverse the change, according to an assessment by blockchain security firm Hacken.

The multisig does not hold user funds, but it controls the USDT contract itself: the power to mint tokens, freeze addresses, and reassign ownership. A two-key compromise would let an attacker act across the entire deployment without touching any individual wallet. Hacken gave USDT a cybersecurity score of 3.3 out of 10.

Why it matters

The risk crosses chains because Tether reuses the same six signing keys across Ethereum, Avalanche, and Celo. A compromise involving keys used on Celo or Avalanche could also authorize a separate administrative transaction on Ethereum, according to Hacken smart-contract auditor Seher Saylık. "There is no built-in delay, cancellation process, or reliable way to undo the changes."

The Hacken review found no evidence that any key has been compromised or that any security incident has occurred. But it noted no link between reserves and code execution: USDT's smart contracts have no automated proof-of-reserve checks and no cap on token creation. Once signers authorize a transaction, the contract will mint any amount without requiring proof of bank deposits.

Market impact

Bluechip raised Tether's corporate grade to C from D after a KPMG audit found reserves exceeded liabilities by $6.8 billion as of Dec. 31, 2025. It is the first review under Bluechip's expanded SMIDGE methodology, which folds Hacken's technical-risk scoring into its financial and governance review. Benjamin Levit, CEO of Bluechip: "Stablecoin ratings have always covered the financial side. With Hacken's technical data now integrated into our methodology, we can finally rate the full picture."

S&P Global downgraded USDT to the weakest possible score on its stablecoin stability scale in November, citing peg risk, bitcoin exposure, and reserve disclosure gaps.

Related tokens
$USDT

Frequently asked questions

  1. How much USDT is at risk according to the Hacken assessment?

    About $91.3 billion of USDT on Tron, roughly half of all circulating supply, is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, Hacken found.

  2. What exactly can two signing keys do to the USDT contract?

    They can change the contract owner, mint new USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee, or redirect token balances, without any individual user wallet being touched.

  3. Does the risk extend beyond Tron?

    Yes. Tether reuses the same six signing keys across Ethereum, Avalanche, and Celo, so a key compromise on one chain could authorize an administrative transaction on another.

  4. Why did Tether's rating just go up if the cybersecurity score is so low?

    Bluechip's corporate grade rose to C from D after a KPMG audit found reserves exceeded liabilities by $6.8B as of Dec. 31, 2025. The grade reflects financial backing, not on-chain key architecture.

  5. Has Tether actually been hacked on these keys?

    No. Hacken found no evidence that any key has been compromised or that any security incident has occurred. The warning is about the architecture, not a live exploit.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →