Approximately half of all circulating USDT, amounting to roughly $91.3 billion on the Tron blockchain, is managed by a contract whose administrative privileges could be seized by anyone possessing two signing keys, devoid of any integrated delay, cancellation window, or reversal mechanism, based on an evaluation by blockchain security firm Hacken.
Even though Hacken pointed out various cybersecurity concerns regarding the blockchain infrastructure of the world’s primary stablecoin, rating agency Bluechip elevated issuer Tether’s corporate standing from D to C, following a financial audit conducted by KPMG US, one of the premier four global auditing entities. The business is the pioneer to be evaluated by Bluechip under a fresh framework that combines a financial assessment with an evaluation by Hacken. The review uncovered no indications that any key has been compromised or that any security event has transpired.
The multisig wallet does not house user funds; instead, it governs the USDT contract itself—possessing the authority to mint tokens, freeze addresses, and reassign ownership—which explains why a two-key compromise would empower a malicious actor to operate across the entire deployment without interacting with any singular wallet.
“There is no integrated delay, cancellation workflow, or dependable method to revert the alterations,” remarked Seher Saylık, a smart contract auditor at Hacken, in a Telegram communication with CoinDesk.
Tether did not promptly reply to a request for feedback.
Hacken mentioned that it has not yet finalized a comparable evaluation of Circle’s USDC. Bluechip’s B+ rating for USDC cannot be interpreted as a direct technical comparison because it was granted under Bluechip’s former methodology, prior to the integration of Hacken’s cybersecurity metric.
Saylık explained that a bad actor could initially modify the contract owner to an address under their control, locking out the legitimate signers of Tether. The perpetrator could subsequently mint USDT, halt or restart transfers, freeze addresses, erase frozen balances, apply a transfer fee, or redirect token balances and transfers, she noted. The intruder would not require access to the wallets of individual users.
“Fortunately for Tether, the KPMG audit and the novel scoring system improved the standing, but the architecture remained unchanged,” stated Leo Fan, founder and chief executive officer of Cysic.xyz and former head of quantum resilience at Algorand. “Half of the supply, approximately $91 billion on Tron, continues to reside behind two keys lacking a timelock, and nothing on-chain appears to hinder what those keys might mint tomorrow.”
This exact vulnerability can propagate across Ethereum, Avalanche, and Celo because Tether utilizes the identical six signing keys across all three networks, according to Saylık. A breach involving keys utilized on Celo or Avalanche could likewise be leveraged to authorize an independent administrative transaction on Ethereum.
While Tether routinely freezes blacklisted addresses during law enforcement investigations, security examiners emphasize that this safeguard offers zero defense during a key breach. Because a two-key breach permits an adversary to reassign contract ownership, it could permanently strip Tether of its administrative authorities and incapacitate its capacity to freeze assets, blockchain consultant Ethan Whitcomb clarified in a November report.
While Hacken authenticated the off-chain financial backing of Tether, it observed no correlation between reserves and code execution: the smart contracts of USDT feature no automated “proof-of-reserve” validations in place and no maximum ceiling on token generation, implying that once signers greenlight a transaction, the contract will mint any volume without demanding proof of bank deposits.
These discoveries illustrate a vulnerability that has impacted other stablecoin creators. Resolv’s stablecoin plummeted 70% in March after a malicious actor minted tokens and extracted $25 million in ETH. StablR unveiled unauthorized creation of USDR and EURR following a security breach in May.
The rating
Regarding the financial aspect of the evaluation, the rating was upgraded because KPMG determined that the reserves of Tether International, S.A. de C.V. exceeded its liabilities by $6.8 billion as of December 31, 2025.
The updated score marks the inaugural application of Bluechip’s expanded SMIDGE framework, which integrates the technical-risk evaluation of Hacken alongside a financial and governance review. This strategy couples an appraisal of an issuer’s reserves with an inspection of the code and administrative controls governing stablecoin issuance.
Bluechip and Hacken revealed their collaboration in August, stating that the technical score would evaluate aspects encompassing smart-contract reliability, supply integrity, administrative key oversight, and off-chain infrastructure.
Bluechip had maintained USDT at its D rating for years. The KPMG audit fulfills one of the prerequisites previously established by Bluechip for an upgrade: a comprehensive audit of Tether’s consolidated financial reports by an independent auditor.
Boasting roughly $184.6 billion in circulating supply, USDT stands as a vital source of liquidity within cryptocurrency.
“Stablecoin evaluations have traditionally focused exclusively on the financial side,” remarked Benjamin Levit, chief executive officer of Bluechip. “With Hacken’s technical metrics now embedded in our framework, we can finally evaluate the complete picture.”
S&P Global Ratings downgraded USDT to the most vulnerable score on its stablecoin stability spectrum in November owing to apprehensions regarding its capacity to preserve a price peg to the United States dollar, elevated exposure to volatile assets such as bitcoin, and persistent deficiencies in reserve disclosure. Tether “strongly” contested this, stating that the rating agency utilized a legacy framework failing to capture the nature, magnitude, and macroeconomic significance of digitally native currency.
Anvil: The Missing Collateral Layer
Anvil serves as a shared on-chain collateral layer constructed upon a programmable letter of credit: utilizing reserve assets as a guarantee—no loan, no interest, preserving custody and yield.
Why it matters:
Anvil functions as a shared on-chain collateral layer created on a programmable letter of credit: reserve assets serving as protection—no loan, no interest, retaining custody alongside yield.
Originally published at https://www.coindesk.com/tech/2026/09/04/tether-receives-bluechip-rating-upgrade-but-hacken-finds-major-key-security-gaps.