Advertisement

$91B USDT Threatened by Potential Two-Key Security Breach

A new stablecoin rating framework is combining traditional financial audits with Web3 security reviews to assess both the reserves backing stablecoins and the technology controlling their issuance.

According to blockchain security firm Hacken, roughly half of USDT’s circulating supply — about $91.3 billion on the Tron network — is controlled by a smart contract that could potentially be taken over if an attacker obtained two signing keys.

The contract reportedly lacks a built-in timelock, cancellation period or dependable method for reversing an unauthorized administrative change.

Despite identifying several cybersecurity concerns in Tether’s infrastructure, rating agency Bluechip upgraded Tether’s corporate grade to C from D following a financial audit by KPMG US, one of the Big Four accounting firms.

Tether is the first stablecoin issuer evaluated under Bluechip’s revised methodology, which combines KPMG’s financial findings with Hacken’s technical assessment. Hacken said it found no evidence that any administrative keys had been compromised or that an actual security incident had occurred.

The multisig wallet does not directly store users’ funds. Instead, it controls the USDT smart contract and holds authority over functions including minting tokens, freezing addresses and transferring ownership.

That distinction is important because an attacker who obtained two authorized keys could potentially take control of the entire USDT deployment without gaining access to individual customer wallets.

“There is no built-in delay, cancellation process, or reliable way to undo the changes,” Seher Saylık, a smart-contract auditor at Hacken, told CoinDesk.

Tether had not immediately responded to a request for comment.

Hacken has not yet carried out a comparable review of Circle’s USDC. Bluechip’s B+ rating for USDC also should not be viewed as a direct technical comparison because that assessment was conducted under the agency’s previous methodology, before Hacken’s cybersecurity factor was introduced.

How a Two-Key Attack Could Work

Saylık said an attacker with two valid signing keys could first change the USDT contract’s owner to an address under their control. That could effectively remove Tether’s legitimate administrators from control of the contract.

From there, the attacker could potentially mint new USDT, stop or restart transfers, freeze addresses, remove frozen balances, add transfer fees or redirect token balances and transactions.

Importantly, the attacker would not need to compromise individual users’ wallets to carry out these actions.

Leo Fan, founder and CEO of Cysic.xyz and a former quantum-resilience lead at Algorand, said the rating upgrade improved Tether’s assessment without changing the underlying architecture.

The concern also extends beyond Tron. Saylık said Tether uses the same six signing keys across Ethereum, Avalanche and Celo. As a result, compromising keys associated with one of those networks could potentially allow an attacker to authorize an administrative transaction affecting another network.

Tether’s ability to freeze blacklisted addresses also would not necessarily protect the system during a key compromise.

The issuer routinely freezes addresses associated with law-enforcement cases, but a successful two-key attack could allow an attacker to transfer ownership of the contract. That could potentially strip Tether of its administrative privileges and prevent it from freezing funds, blockchain adviser Ethan Whitcomb said in a November report.

Hacken also found a separation between Tether’s financial reserves and its smart-contract operations.

While the firm validated Tether’s off-chain financial backing, USDT’s smart contracts reportedly do not automatically verify reserves through an on-chain proof-of-reserves system. They also lack a fixed ceiling on token creation.

This means an authorized transaction could theoretically instruct the contract to mint any amount of USDT without requiring on-chain confirmation that equivalent funds exist in bank accounts.

Similar vulnerabilities have emerged elsewhere in the stablecoin market. Resolv’s stablecoin dropped about 70% in March after an attacker minted tokens and extracted $25 million worth of ETH. StablR also disclosed unauthorized issuance of its USDR and EURR tokens following a security breach in May.

Why Tether’s Rating Improved

The upgrade was driven partly by Tether’s financial position. KPMG found that Tether International, S.A. de C.V.’s reserves exceeded its liabilities by $6.8 billion as of December 31, 2025.

Bluechip’s new C rating represents the first application of its expanded SMIDGE methodology. The system combines financial and governance analysis with Hacken’s assessment of technical risks.

The approach is designed to examine not only the assets backing a stablecoin but also the code, administrative controls and infrastructure responsible for managing its supply.

Bluechip and Hacken announced their partnership in August, saying the technical assessment would cover smart-contract reliability, supply integrity, administrative key security and off-chain infrastructure.

Bluechip had previously maintained a D rating for USDT for several years. The KPMG audit addressed one of the conditions the rating agency had identified for a potential upgrade: an independent, full-scope audit of Tether’s consolidated financial statements.

With approximately $184.6 billion in outstanding supply, USDT remains one of the crypto market’s largest sources of liquidity.

Bluechip CEO Benjamin Levit said stablecoin ratings have traditionally concentrated on financial factors, while the integration of Hacken’s technical analysis allows the agency to evaluate a broader range of risks.

The updated assessment comes after S&P Global Ratings gave USDT its weakest possible score on its stablecoin stability scale in November. S&P cited concerns over Tether’s ability to maintain its dollar peg, exposure to riskier assets such as Bitcoin and continued gaps in reserve disclosures.

Tether strongly rejected that assessment, arguing that S&P’s framework relied on an outdated approach that failed to reflect the scale, structure and broader economic significance of digital-native money.