Half of USDT Held in 2-of-3 Multisig Contract
Blockchain security firm Hacken released an assessment report revealing that approximately half of all USDT in circulation — about $91.3 billion on the Tron network — is controlled by a 2-of-3 multisig contract. The contract lacks built-in delay, cancellation, or reliable revocation mechanisms. An attacker who compromises two of the three signer keys could change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees without accessing any user wallets.
Cross-Chain Key Reuse Amplifies Risk
Hacken also found that Tether reuses the same set of six signer keys across Ethereum, Avalanche, and Celo. A leak on one chain could expose USDT contracts on others, potentially causing cross-chain contagion.
Bluechip Upgrades Tether Rating, But Technical Concerns Remain
Stablecoin rating agency Bluechip upgraded Tether's corporate rating from D to C, citing a KPMG audit showing that as of December 31, 2025, Tether's reserves exceeded liabilities by $6.8 billion. This is the first rating under Bluechip's expanded SMIDGE methodology, which incorporates Hacken's technical risk analysis.
Hacken Gives USDT Low Security Score
Despite the upgraded corporate rating, Hacken assigned USDT a cybersecurity score of only 3.3 out of 10. The report noted that the USDT smart contract has no automatic reserve proof check and no token minting cap. Once signers authorize a transaction, the contract can mint any amount of tokens without bank reserve proof. Hacken has not yet completed an equivalent assessment of Circle's USDC. Bluechip's previous B+ rating for USDC was based on an older methodology and cannot be directly compared on technical grounds.

