Hackers Could Seize $91B in USDT Through Two-Key Attack

A new stablecoin rating system is combining traditional financial audits with blockchain security assessments to provide a broader view of issuer risk, covering both off-chain reserves and on-chain controls.

Blockchain security firm Hacken found that roughly half of USDT’s circulating supply, worth about $91.3 billion on Tron, is controlled by a smart contract whose administrative authority could potentially be captured if an attacker obtained two signing keys.

The contract does not reportedly include a timelock, cancellation period or dependable mechanism for reversing an unauthorized ownership change.

Despite flagging several cybersecurity weaknesses in Tether’s infrastructure, rating agency Bluechip raised Tether’s corporate rating to C from D following a financial audit by KPMG US.

Tether became the first issuer reviewed under Bluechip’s updated methodology, which combines KPMG’s financial assessment with Hacken’s technical security analysis. Hacken said it found no evidence that the relevant keys had been compromised or that a security incident had occurred.

The multisignature setup does not directly custody users’ USDT. Instead, it controls the underlying token contract and therefore has authority over critical functions such as minting, freezing addresses and changing ownership.

That means a successful two-key compromise could potentially give an attacker control over the entire deployment without requiring access to customers’ individual wallets.

“There is no built-in delay, cancellation process, or reliable way to undo the changes,” Seher Saylık, a smart-contract auditor at Hacken, told CoinDesk.

Tether had not immediately commented on the findings.

Hacken has yet to conduct a comparable technical assessment of Circle’s USDC. Bluechip’s B+ rating for USDC also is not directly comparable with the new USDT score because it was issued under the agency’s previous methodology, before Hacken’s cybersecurity component was added.

What a Two-Key Compromise Could Enable

Saylık said an attacker controlling two authorized keys could first replace the USDT contract owner with an address they control. That would potentially remove Tether’s legitimate administrators from their ability to manage the contract.

The attacker could then potentially mint additional USDT, pause or restart transfers, freeze addresses, remove frozen balances, introduce transfer fees or redirect token balances and transactions.

Such an attack would not require access to individual users’ wallets.

Leo Fan, CEO and founder of Cysic.xyz and a former quantum-resilience lead at Algorand, said the financial audit and revised rating methodology improved Tether’s score but did not change the underlying security architecture.

The key-management issue may also span multiple blockchains. Saylık said Tether reuses the same six signing keys across Ethereum, Avalanche and Celo. A compromise involving keys used on one network could therefore potentially be leveraged to authorize an administrative transaction on another.

Tether’s address-freezing capabilities would also not necessarily protect the system in the event of a key compromise.

Although the issuer regularly freezes addresses linked to law-enforcement investigations, an attacker who gains sufficient administrative control could transfer ownership of the contract and potentially remove Tether’s ability to manage or freeze funds, according to blockchain adviser Ethan Whitcomb.

Hacken also identified a separation between Tether’s off-chain reserves and the execution of its smart contracts.

The security firm confirmed Tether’s financial backing but noted that USDT’s contracts do not automatically verify reserves through an on-chain proof-of-reserves system. The contracts also reportedly have no hard limit on how many tokens can be created.

Consequently, once the required signers approve an issuance transaction, the contract could theoretically mint any amount of USDT without independently confirming that matching bank reserves exist.

The broader stablecoin industry has experienced similar issuance-related security incidents. Resolv’s stablecoin lost around 70% of its value in March after an attacker minted tokens and withdrew $25 million in ETH. StablR also reported unauthorized issuance of USDR and EURR after a security breach in May.

Why Tether Received a Higher Rating

Tether’s improved grade was partly driven by the results of KPMG’s financial audit. The accounting firm found that Tether International, S.A. de C.V. had reserves exceeding its liabilities by $6.8 billion as of December 31, 2025.

The C rating is the first issued under Bluechip’s expanded SMIDGE framework, which combines financial and governance reviews with technical-risk analysis from Hacken.

The methodology evaluates not only the assets backing a stablecoin but also the code and administrative systems responsible for issuing and managing its supply.

Bluechip and Hacken announced their partnership in August. Their technical assessment covers areas including smart-contract reliability, supply integrity, administrative key management and off-chain infrastructure.

Bluechip had kept USDT at a D rating for years. The KPMG audit met one of the agency’s previously stated requirements for an upgrade: an independent, full-scope audit of Tether’s consolidated financial statements.

With roughly $184.6 billion in outstanding supply, USDT remains a critical source of liquidity throughout the cryptocurrency market.

Bluechip CEO Benjamin Levit said stablecoin ratings have traditionally focused on financial strength, while incorporating technical data from Hacken allows the agency to evaluate a wider range of risks.

The updated rating comes after S&P Global Ratings assigned USDT its lowest possible score on its stablecoin stability scale in November. S&P cited concerns about Tether’s ability to maintain its dollar peg, exposure to volatile assets such as Bitcoin and gaps in reserve disclosures.

Tether strongly disputed S&P’s assessment, arguing that the agency relied on an outdated framework that did not adequately account for the scale, structure and broader economic role of digital-native money.