What to Know
- About $91.3 billion of USDT on Tron is controlled by a contract whose administrative powers could be seized by anyone holding two signing keys.
- Hacken found that the relevant setup is a 2-of-3 multisig arrangement with no built-in delay, cancellation window or reversal mechanism.
- The contract does not hold user funds directly, but it controls minting, freezing, ownership reassignment and other administrative functions for the USDT deployment.
- Hacken found no evidence that any signing key has been compromised and no evidence that a security incident has occurred.
- Bluechip raised Tether’s corporate grade to C from D after a KPMG US audit found Tether International, S.A. de C.V.’s reserves exceeded liabilities by $6.8 billion as of Dec. 31, 2025.
- Hacken assigned USDT a cybersecurity score of 3.3 out of 10 under Bluechip’s expanded methodology.
- Hacken warned that reused signing keys could extend administrative risk across Ethereum, Avalanche and Celo.
- USDT has about $184.6 billion in outstanding supply, making it one of the most important liquidity instruments in the crypto market.
USDT’s Tron Deployment Draws Fresh Security Scrutiny
A new security review has put a spotlight on the administrative controls behind USDT on Tron, where roughly $91.3 billion of the stablecoin is governed by a contract that can be controlled through a 2-of-3 multisig wallet. The concern is not that user wallets have been breached, nor that reserves are missing. Instead, the issue is architectural: if two signing keys were compromised, an attacker could gain administrative control over the contract without any built-in waiting period, cancellation process or reliable on-chain reversal path.
For a stablecoin as widely used as USDT, that distinction matters. The multisig does not custody individual user balances in the ordinary sense. It controls the contract itself, including functions that can mint tokens, freeze addresses, resume or halt transfers and reassign ownership. In practical terms, the risk identified by Hacken is that control over two keys could allow an attacker to act at the contract level, rather than needing to compromise users one by one.
Hacken did not find evidence that any key has been compromised. It also did not identify an active security incident. The findings instead describe a potential failure mode in the administrative design of one of crypto’s most important assets. For market participants, that creates a complicated picture: USDT remains deeply embedded in trading, payments and decentralized finance activity, while its technical governance controls are now facing renewed scrutiny.
Bluechip Raises Tether’s Grade After KPMG Audit
The security concerns emerged alongside a ratings upgrade for Tether. Bluechip raised Tether’s corporate grade to C from D after a KPMG US audit found that Tether International, S.A. de C.V.’s reserves exceeded its liabilities by $6.8 billion as of Dec. 31, 2025. The audit addressed a major condition Bluechip had previously set for an upgrade: a full-scope audit of consolidated financial statements by an independent auditor.
The upgrade reflects Bluechip’s expanded SMIDGE methodology, which now combines financial and governance review with technical-risk analysis from Hacken. That framework is designed to assess both off-chain backing and on-chain infrastructure, a combination increasingly seen as essential for stablecoin evaluation. A stablecoin can be well backed financially while still carrying smart-contract or administrative risks that affect how tokens are issued, frozen or governed.
Bluechip had kept USDT at a D rating for years before the KPMG audit moved the corporate grade higher. Under the updated framework, however, the financial improvement sits beside Hacken’s separate technical assessment, which gave USDT a cybersecurity score of 3.3 out of 10. The result is a more nuanced profile: stronger audited reserve coverage on one side, and key-management concerns on the other.
Why Two Signing Keys Matter
A 2-of-3 multisig setup means that two out of three authorized signatures can approve a given administrative action. Multisig structures are widely used in crypto because they can reduce reliance on a single private key. However, their security depends on how keys are stored, whether signers are independent, whether emergency controls exist and whether critical changes are subject to time delays or veto windows.
In the USDT on Tron case, Hacken’s concern is that there is no built-in delay, cancellation process or reliable way to undo changes after the required signatures are provided. Seher Saylık, a smart contract auditor at Hacken, said an attacker with the necessary keys could first change the contract owner to an address they control, locking out Tether’s legitimate signers. From there, the attacker could mint USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee or redirect token balances and transfers.
The absence of a timelock is central to the concern. Timelocks are often used to create a visible delay between approval and execution, allowing teams, users or monitoring systems time to react if a malicious or mistaken transaction is queued. Without such a delay, a validly signed administrative action can take effect immediately, leaving little opportunity for intervention if keys are misused.
Cross-Chain Key Reuse Adds Another Layer
Hacken also warned that the same risk can extend beyond Tron because Tether reuses the same six signing keys across Ethereum, Avalanche and Celo. Saylık said a compromise involving keys used on Celo or Avalanche could also be used to authorize a separate administrative transaction on Ethereum. That kind of key reuse can create correlated risk across deployments, even when each network has its own contracts and operating environment.
Cross-chain stablecoin issuance adds operational complexity. Issuers must maintain administrative control across several blockchains while protecting keys, managing upgrades and responding to law enforcement requests or emergency events. Reusing keys may simplify administration, but security auditors often prefer stronger separation so that a compromise in one environment does not automatically create risk elsewhere.
Bluechip’s B+ rating for USDC has not been treated as a direct technical comparison under this new approach because that rating was assigned under Bluechip’s earlier methodology, before Hacken’s cybersecurity factor was introduced. Hacken has not completed a comparable assessment of Circle’s USDC. That means the current findings should be viewed as specific to the reviewed USDT setup rather than as a full ranking of all major stablecoins under the same technical framework.
Freezing Powers Do Not Solve a Key Breach
Tether routinely freezes blacklisted addresses in law enforcement cases, and those controls are an important part of how centralized stablecoins operate. However, auditors caution that the ability to freeze addresses does not protect the system if the administrative keys themselves are compromised. If an attacker can reassign contract ownership, the legitimate issuer may no longer be able to use freezing powers to contain the damage.
Blockchain adviser Ethan Whitcomb explained in a November report that a two-key compromise could permanently strip Tether of its administrative rights and disable its ability to freeze funds. That scenario illustrates why key security is not only a matter of protecting issuer authority. It is also linked to the issuer’s ability to respond to illicit activity, operational mistakes or wider market disruption.
Hacken also noted that USDT’s smart contracts have no automated proof-of-reserve checks and no cap on token creation. The implication is that once signers authorize a minting transaction, the contract will mint the requested amount without requiring proof of corresponding bank deposits. That does not mean unauthorized minting has occurred. It means the code does not independently verify reserves before executing issuance.
Stablecoin Market Context
USDT’s scale makes any discussion of its controls significant for crypto markets. With about $184.6 billion in outstanding supply, USDT is one of the sector’s most important sources of liquidity. Traders use it to move between exchanges, settle transactions, access decentralized finance markets and manage exposure without leaving the crypto ecosystem. Because of that role, operational trust in USDT’s issuance and administration has market-wide implications.
Other stablecoin incidents have shown how quickly confidence can be damaged when issuance controls fail. Resolv’s stablecoin fell 70% in March after an attacker minted tokens and extracted $25 million in ETH. StablR disclosed unauthorized issuance of USDR and EURR following a security breach in May. Those cases are not identical to USDT’s situation, but they underscore why auditors focus on minting controls, administrative keys and safeguards around privileged functions.
The debate also comes after S&P Global Ratings downgraded USDT to the weakest possible score on its stablecoin stability scale in November. That action cited concerns about the ability to maintain a price peg to the U.S. dollar, increased exposure to risky assets such as bitcoin and ongoing gaps in reserve disclosure. Tether strongly disagreed, saying the rating agency used a legacy framework that does not capture the nature, scale and macroeconomic importance of digitally native money.
What the Review Means for Market Participants
For traders and institutions, the key takeaway is that stablecoin risk is no longer only about reserves. Financial backing remains vital, but smart-contract permissions, key management, timelocks, supply controls and cross-chain administrative design are becoming equally important parts of the risk conversation. Bluechip’s new framework reflects that shift by combining Wall Street-style financial auditing with Web3 code review.
The ratings outcome may look mixed because it is mixed. Tether received a higher corporate grade after a major audit found reserves exceeded liabilities, yet the same broader review highlighted cybersecurity concerns around the infrastructure that governs a large portion of USDT supply. Market participants evaluating USDT may therefore need to separate reserve confidence from technical-control confidence, rather than treating stablecoin safety as a single measure.
FXCOINZ will continue monitoring how stablecoin issuers respond to growing pressure for stronger technical controls. Possible mitigations often discussed by security professionals include timelocks, stronger key separation across chains, clearer emergency procedures and on-chain mechanisms that create more transparency around administrative changes. Any such changes would need to be assessed on their own merits and against the operational realities of running a global stablecoin.
Frequently Asked Questions (FAQs)
What did Hacken identify in USDT’s Tron setup?
Hacken identified that about $91.3 billion of USDT on Tron is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, with no built-in delay, cancellation window or reliable reversal mechanism.
Does the review say USDT was hacked?
No. Hacken found no evidence that any signing key has been compromised and no evidence that any security incident has occurred. The findings describe a potential administrative-control risk rather than an active breach.
What can the USDT contract administrator do?
The administrator can perform powerful functions such as minting tokens, freezing addresses, halting or resuming transfers and reassigning ownership. That is why control over the administrative keys is so important.
Why did Bluechip upgrade Tether’s rating?
Bluechip raised Tether’s corporate grade to C from D after a KPMG US audit found that Tether International, S.A. de C.V.’s reserves exceeded liabilities by $6.8 billion as of Dec. 31, 2025.
What cybersecurity score did Hacken give USDT?
Hacken gave USDT a cybersecurity score of 3.3 out of 10 under Bluechip’s expanded methodology, which now includes technical-risk analysis alongside financial and governance review.
Why is key reuse across blockchains a concern?
Hacken warned that Tether reuses the same six signing keys across Ethereum, Avalanche and Celo. A compromise involving keys used on one of those networks could potentially be used to authorize administrative action on another.
Do USDT smart contracts automatically check reserves before minting?
Hacken noted that USDT’s smart contracts have no automated proof-of-reserve checks and no cap on token creation. Once authorized signers approve a minting transaction, the contract can execute it without requiring proof of bank deposits.
How large is USDT’s total supply?
USDT has about $184.6 billion in outstanding supply, making it one of the most important liquidity instruments in the crypto market.
Why does this matter to crypto traders?
USDT is widely used for liquidity, settlement and trading activity. Any credible concern about its administrative controls can affect how market participants evaluate operational risk, even when reserve backing receives a more favorable assessment.
Photo by Alesia Kozik on Pexels
