Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$78,812▲ 0.34%ETH$2,496▲ 0.25%SOL$103.62▼ 0.10%TOTAL CRYPTO$2.7T▼ 2.81%S&P 5007,645.58▼ 1.44%NASDAQ26,266.48▼ 1.59%DOW52,523.13▼ 2.80%GOLD4,461.40▲ 2.28%WTI95.23▲ 15.95%BRENT100.25▲ 14.28%EUR/USD1.1643▲ 1.02%USD/JPY153.51▼ 3.09%DXY98.75▼ 1.06%

Half of All USDT Sits Behind Two Signing Keys, Report Finds

A Hacken review found $91.3 billion of USDT on Tron is controlled by a contract two compromised keys could seize, with no delay or reversal built in.

PartnerSurfshark VPN

Roughly $91.3 billion of USDT on the Tron network, about half the stablecoin circulating supply, is governed by a contract that anyone holding two signing keys could seize, according to a security review by blockchain firm Hacken. The keys control minting, address freezing and ownership of the contract, with no timelock, cancellation window or reversal mechanism on chain.

What two keys would buy an attacker

The multisig does not hold user funds. It controls the USDT contract itself, which is why the blast radius is so large. An attacker with two of the administrative keys could mint new tokens, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee or redirect balances, all without touching a single user wallet.

The same key set is reused across Ethereum, Avalanche and Celo, so a compromise would not stay confined to Tron. Hacken scored USDT 3.3 out of 10 on cybersecurity, a low mark for an asset this size.

Because a two-key compromise allows reassigning contract ownership, an attacker could also permanently strip Tether of its administrative rights and end its own ability to freeze funds, an outcome reviewers noted has no on-chain remedy. There would be no pause button and no rollback, only whatever off-chain response exchanges and issuers could improvise in the minutes after the keys were used.

Rating upgraded anyway

The review is part of a new framework from rating firm Bluechip that pairs a Wall Street-style financial audit with a Web3 code review. On the financial side, KPMG US found Tether International reserves exceeded liabilities by $6.8 billion as of December 31, 2025, and Bluechip raised the issuer corporate grade to C from D.

Bluechip and Hacken found no evidence that any key has been compromised or that a security incident has occurred. The point of the report is architecture, not a breach that already happened. Tether is the first issuer reviewed under the combined system, which the rating firm describes as an attempt to judge both the balance sheet and the code that holds the asset together.

The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not, said Leo Fan, founder of Cysic and former lead on quantum resilience at Algorand. Half the supply, about $91 billion on Tron, still sits behind two keys with no timelock and nothing on chain impeding what those keys can mint tomorrow, he said.

Measure Result
USDT on Tron behind 2-key control $91.3 billion
Hacken cybersecurity score 3.3 / 10
Bluechip corporate grade C (up from D)
KPMG reserve surplus $6.8 billion
Known key compromises None

Context for the finding

USDT circulation exceeds $180 billion, making it the liquidity backbone of crypto trading. A hostile mint or mass freeze through the contract would hit every market that uses the token as a quote or settlement asset, which is most of them. Traders move in and out of volatile assets through USDT, exchanges quote against it, and payment corridors from Latin America to Asia run on it daily.

The report lands amid other scrutiny of the issuer. In August, two Thai businessmen sued Tether, alleging it froze about $42.4 million in USDT after an informal law enforcement request without a warrant, a freeze that reportedly originated from a request made in October 2025. Tether completed the KPMG audit the same month, an effort to answer years of questions about reserve backing.

Experts quoted in the review also flagged longer-horizon risks, including the possibility that advances in quantum computing could eventually threaten elliptic-curve signing keys of this kind. No date was given for when that risk becomes practical, but the absence of a timelock means there is no built-in window to detect and react to a key compromise even today.

Tether has not publicly responded to the Hacken findings. Any structural fix would mean migrating the contract or its admin controls across several chains while keeping a multi-hundred-billion-dollar asset liquid, a costly and delicate operation that no major issuer has completed at this scale. Until then, the security of half the stablecoin market rests on two keys held by one company, and on the assumption nobody gets both.

SourcesCoinDesk; Hacken review; Bluechip; Crypto Briefing
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Harmony Moves to Shut Its Blockchain, Migrate ONE to Ethereum Read →