ChainCatcher report: Blockchain security firm Hacken has released an assessment report indicating that approximately half of the circulating USDT (around $91.3 billion on the Tron network) is controlled by a 2-of-3 multisignature contract lacking built-in delays, cancellation procedures, or reliable revocation mechanisms. An attacker only needs to compromise two signature keys to change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees—without accessing any user wallets. Hacken also found that Tether reuses the same set of six signature keys across Ethereum, Avalanche, and Celo, creating potential for cross-chain risk propagation. Meanwhile, the stablecoin rating agency Bluechip upgraded Tether’s corporate rating from D to C, citing KPMG’s audit showing Tether’s reserves exceeded liabilities by $6.8 billion as of December 31, 2025. This marks Bluechip’s first use of its expanded SMIDGE methodology, which incorporates Hacken’s technical risk analysis. However, Hacken assigned USDT a cybersecurity score of only 3.3 out of 10, noting that the USDT smart contract lacks automated reserve proof verification and has no upper limit on token minting—once signers authorize a transaction, the contract can mint any amount of tokens without requiring bank reserve backing. Hacken stated it has not yet completed a comparable assessment of Circle’s USDC; Bluechip’s previous B+ rating for USDC was based on an older methodology and cannot be directly used for technical comparison.
Hacken Report: Half of USDT Controlled by Two Signature Keys
ChaincatcherShare
Hacken’s report highlights contract security concerns with USDT, revealing that nearly half of the USDT on Tron is controlled by a 2-of-3 smart contract. The setup lacks delay or revocation mechanisms, exposing risks such as unauthorized ownership changes and unauthorized minting. Tether reused six signature keys across multiple blockchains, increasing cross-chain vulnerabilities. Bluechip upgraded Tether’s rating to C, citing improved reserves, while Hacken rated USDT’s smart contract cybersecurity at 3.3 out of 10. The firm has not yet assessed USDC using its updated methodology.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
