Hacken Report: Half of USDT is controlled by only two signing keys
Blockchain security company Hacken released an assessment report indicating that approximately half of the circulating USDT (about $91.3 billion on the Tron network) is controlled by a 2-of-3 multi-signature contract, which lacks built-in delays, cancellation processes, or reliable revocation mechanisms. Attackers only need to compromise two signature keys to change contract ownership, mint tokens, freeze addresses, clear frozen balances, or set transfer fees without accessing any user wallets. Hacken also discovered that Tether reuses the same set of six signature keys across three chains: Ethereum, Avalanche, and Celo, posing a risk of cross-chain spread.Meanwhile, stablecoin rating agency Bluechip upgraded Tether's company rating from D to C, citing that KPMG's audit showed Tether's reserves exceeded liabilities by $6.8 billion as of December 31, 2025. This is the first time Bluechip has adopted the expanded SMIDGE methodology, which incorporates Hacken's technical risk analysis. However, Hacken only gave USDT a cybersecurity score of 3.3 out of 10 and pointed out that the USDT smart contract does not have automatic reserve proof checks or a token minting cap. Once signers authorize a transaction, the contract can mint an unlimited number of tokens without a bank reserve proof.Hacken stated that it has not yet completed an equivalent assessment of Circle's USDC, and Bluechip's previous B+ rating for USDC was based on an old methodology, which cannot be directly used for technical comparison.