About half of all circulating $USDT, roughly $91.3 billion on the Tron network, is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, with no built-in delay, cancellation window or way to reverse the change, according to an assessment by blockchain security firm Hacken.
Even though the world's largest stablecoin received only 3.3 out of 10 on cybersecurity, rating company Bluechip raised issuer Tether's corporate grade to C from D, after a financial audit by KPMG US, one of the Big Four global auditing firms. The company is the first to be reviewed by Bluechip under a new system that pairs a financial review with analysis by Hacken. The review found no evidence that any key has been compromised or that any security incident has occurred.
The multisig does not hold user funds, it controls the $USDT contract itself — the power to mint tokens, freeze addresses and reassign ownership — which is why a two-key compromise would let an attacker act across the entire deployment without touching any individual wallet.
“There is no built-in delay, cancellation process, or reliable way to undo the changes,” Seher Saylık, a smart contract auditor at Hacken, told CoinDesk via Telegram.
Tether did not immediately respond to a request for comment.
Hacken said it has not yet completed a comparable assessment of Circle’s $USDC. Bluechip’s B+ rating for $USDC cannot be treated as a direct technical comparison because it was assigned under Bluechip’s earlier methodology, before Hacken’s cybersecurity factor was introduced.
Saylık said an attacker could first change the contract owner to an address they control, locking out Tether’s legitimate signers. The attacker could then mint $USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee or redirect token balances and transfers, she said. The attacker would not need access to individual users’ wallets.
“The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not,” said Leo Fan, founder and CEO of Cysic.xyz and former lead on quantum resilience at Algorand. “Half the supply, about $91 billion on Tron, still sits behind two keys with no timelock and nothing onchain seems to impede what those keys can mint tomorrow.”
The same risk can extend across Ethereum, Avalanche and Celo because Tether reuses the same six signing keys across all three networks, Saylık said. A compromise involving keys used on Celo or Avalanche could also be used to authorize a separate administrative transaction on Ethereum.