Hacken Report: Half of USDT on Tron Controlled by Vulnerable 2-of-3 Multisig, Tether Reuses Keys Across Chains

Hacken Report: Half of USDT on Tron Controlled by Vulnerable 2-of-3 Multisig, Tether Reuses Keys Across Chains

N
News Editor
2026-09-07 10:42:25
Blockchain security firm Hacken reports that nearly half of USDT in circulation ($91.3B on Tron) is managed by a 2-of-3 multisig contract lacking delay, cancellation, or revocation mechanisms. An attacker compromising two keys could seize full contract control. Tether reuses the same six signer keys on Ethereum, Avalanche, and Celo, posing cross-chain risks. Bluechip upgraded Tether's corporate rating to C after a KPMG audit showed reserves exceeded liabilities by $6.8B. Yet Hacken gave USDT a cybersecurity score of only 3.3/10, citing no automatic reserve proof check and no minting cap. Hacken has not assessed USDC; Bluechip's previous B+ rating for USDC used an older methodology.

Half of USDT Held in 2-of-3 Multisig Contract

Blockchain security firm Hacken released an assessment report revealing that approximately half of all USDT in circulation — about $91.3 billion on the Tron network — is controlled by a 2-of-3 multisig contract. The contract lacks built-in delay, cancellation, or reliable revocation mechanisms. An attacker who compromises two of the three signer keys could change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees without accessing any user wallets.

Cross-Chain Key Reuse Amplifies Risk

Hacken also found that Tether reuses the same set of six signer keys across Ethereum, Avalanche, and Celo. A leak on one chain could expose USDT contracts on others, potentially causing cross-chain contagion.

Bluechip Upgrades Tether Rating, But Technical Concerns Remain

Stablecoin rating agency Bluechip upgraded Tether's corporate rating from D to C, citing a KPMG audit showing that as of December 31, 2025, Tether's reserves exceeded liabilities by $6.8 billion. This is the first rating under Bluechip's expanded SMIDGE methodology, which incorporates Hacken's technical risk analysis.

Hacken Gives USDT Low Security Score

Despite the upgraded corporate rating, Hacken assigned USDT a cybersecurity score of only 3.3 out of 10. The report noted that the USDT smart contract has no automatic reserve proof check and no token minting cap. Once signers authorize a transaction, the contract can mint any amount of tokens without bank reserve proof. Hacken has not yet completed an equivalent assessment of Circle's USDC. Bluechip's previous B+ rating for USDC was based on an older methodology and cannot be directly compared on technical grounds.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.

Hacken Report: Half of USDT on Tron Controlled by Vulnerable 2-of-3 Multisig, Tether Reuses Keys Across Chains | Bit.Fan