USDT Security Alert: Two-Key Exploit Could Put $91B at Risk
A new stablecoin assessment framework is combining financial audits with blockchain security analysis to provide a broader picture of risks surrounding major digital currencies.
The review found that roughly half of USDT’s circulating supply, or about $91.3 billion on the Tron blockchain, relies on administrative controls that could potentially be compromised if an attacker gained access to two signing keys.
According to blockchain security firm Hacken, the system does not include a built-in timelock, cancellation period or dependable mechanism for reversing unauthorized administrative actions.
The findings come as rating agency Bluechip upgraded Tether’s corporate rating from D to C after KPMG US completed a financial audit of the company. Tether was the first stablecoin issuer evaluated under Bluechip’s updated methodology, which combines traditional financial analysis with technical security assessments from Hacken.
Hacken said its review uncovered cybersecurity weaknesses in Tether’s infrastructure but found no evidence that the relevant keys had been compromised or that an actual security incident had taken place.
The multisignature wallet does not directly control users’ USDT holdings. Instead, it has administrative authority over the token’s smart contract, including functions such as minting tokens, freezing addresses and changing ownership.
That distinction is important because compromising two authorized keys could potentially give an attacker control over the contract itself without requiring access to users’ individual wallets.
Seher Saylık, a smart-contract auditor at Hacken, said the architecture lacks an internal delay or cancellation mechanism that could provide additional protection against unauthorized changes.
Tether had not immediately commented on the findings.
The Potential Impact of a Two-Key Compromise
An attacker who obtained two valid signing keys could potentially transfer ownership of the USDT contract to an address under their control. That could allow the attacker to remove Tether’s legitimate administrators from control of the system.
From there, the compromised contract could potentially be used to mint new USDT, suspend or reactivate transfers, freeze addresses, remove frozen balances, introduce transaction fees or redirect balances and transfers.
Such actions could take place without the attacker ever obtaining direct control of individual user wallets.
Leo Fan, founder and CEO of Cysic.xyz and a former quantum-resilience lead at Algorand, said the KPMG audit and revised rating methodology represented progress, but the underlying key-management structure had not changed.
The exposure may also extend beyond Tron. Hacken said Tether uses the same six signing keys across Ethereum, Avalanche and Celo. A compromise of those credentials could therefore create administrative risks across multiple networks.
Tether’s existing address-freezing procedures would not necessarily eliminate the threat. While the company regularly freezes addresses associated with illicit activity, an attacker controlling the contract could potentially change its ownership, strip Tether of administrative authority and interfere with its ability to freeze addresses.
Blockchain adviser Ethan Whitcomb highlighted a similar concern in a report published in November.
Hacken also identified a separate issue involving the relationship between Tether’s reserves and its token issuance system.
Although the firm validated Tether’s off-chain backing, it found no automated mechanism connecting those reserves to on-chain token creation. USDT’s contracts also reportedly lack a hard issuance cap.
This means authorized signers can potentially mint tokens without the smart contract independently confirming that corresponding funds have been deposited into Tether’s reserves.
Other stablecoin projects have experienced related problems. Resolv’s stablecoin lost about 70% of its value in March after an attacker minted tokens and extracted roughly $25 million in ETH. StablR also reported unauthorized USDR and EURR issuance following a breach in May.
Financial Audit Supports Tether Upgrade
KPMG’s financial review provided an important boost to Tether’s rating. The audit found that Tether International, S.A. de C.V. held reserves exceeding its liabilities by $6.8 billion as of December 31, 2025.
Bluechip issued the C rating under its expanded SMIDGE framework, which now combines financial and governance analysis with technical assessments covering smart contracts and infrastructure.
The updated system evaluates factors including smart-contract reliability, token supply integrity, administrative key management and off-chain systems.
Bluechip and Hacken announced their partnership in August as part of the effort to combine traditional stablecoin analysis with Web3 cybersecurity reviews.
Bluechip had previously kept Tether at a D rating for years. The independent KPMG audit satisfied a key requirement for an upgrade by providing a full-scope examination of Tether’s financial statements.
USDT remains one of the largest sources of liquidity in the cryptocurrency market, with its outstanding supply standing at roughly $184.6 billion.
Benjamin Levit, CEO of Bluechip, said stablecoin ratings have historically focused heavily on financial conditions. Incorporating blockchain security data, he said, provides a more complete assessment of issuer risk.
The upgrade comes after S&P Global Ratings gave USDT its weakest score on its stablecoin stability scale in November. S&P pointed to concerns over Tether’s ability to maintain its dollar peg, exposure to volatile assets such as Bitcoin and gaps in reserve disclosures.
Tether disputed that assessment, arguing that S&P’s methodology was outdated and did not adequately account for the size, structure and growing role of digital-native money.
Share this content:













