About half of all circulating USDT, roughly $91.3 billion on the Tron network, is governed by a contract whose administrative controls can be seized by anyone holding two signing keys, with no built-in delay, cancellation window or way to reverse the change, according to an assessment by blockchain security firm Hacken.
Even though Hacken highlighted several cybersecurity findings in the world’s largest stablecoin blockchain infrastructure, rating company Bluechip raised issuer Tether’s corporate grade to C from D, after a financial audit by KPMG US, one of the Big Four global auditing firms. The company is the first to be reviewed by Bluechip under a new system that pairs a financial review with analysis by Hacken. The review found no evidence that any key has been compromised or that any security incident has occurred.
The multisig does not hold user funds, it controls the USDT contract itself — the power to mint tokens, freeze addresses and reassign ownership — which is why a two-key compromise would let an attacker act across the entire deployment without touching any individual wallet.
“There is no built-in delay, cancellation process, or reliable way to undo the changes,” Seher Saylık, a smart contract auditor at Hacken, told CoinDesk via Telegram.
Tether did not immediately respond to a request for comment.
Hacken said it has not yet completed a comparable assessment of Circle’s USDC. Bluechip’s B+ rating for USDC cannot be treated as a direct technical comparison because it was assigned under Bluechip’s earlier methodology, before Hacken’s cybersecurity factor was introduced.
Saylık said an attacker could first change the contract owner to an address they control, locking out Tether’s legitimate signers. The attacker could then mint USDT, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee or redirect token balances and transfers, she said. The attacker would not need access to individual users’ wallets.
“The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not,” said Leo Fan, founder and CEO of Cysic.xyz and former lead on quantum resilience at Algorand. “Half the supply, about $91 billion on Tron, still sits behind two keys with no timelock and nothing onchain seems to impede what those keys can mint tomorrow.”
The same risk can extend across Ethereum, Avalanche and Celo because Tether reuses the same six signing keys across all three networks, Saylık said. A compromise involving keys used on Celo or Avalanche could also be used to authorize a separate administrative transaction on Ethereum.
While Tether routinely freezes blacklisted addresses in law enforcement cases, security auditors note that this mechanism provides no protection during a key breach. Because a two-key compromise allows an attacker to reassign contract ownership. It could permanently strip Tether of its administrative rights and disable its ability to freeze funds, blockchain adviser Ethan Whitcomb explained in a November report.
While Hacken validated Tether’s off-chain financial backing, it noted no link between reserves and code execution: USDT’s smart contracts have no automated “proof-of-reserve” checks in place and no cap on token creation, which means that once signers authorize a transaction, the contract will mint any amount without requiring proof of bank deposits.
The findings show a risk that has affected other stablecoin issuers. Resolv’s stablecoin fell 70% in March after an attacker minted tokens and extracted $25 million in ETH. StablR disclosed unauthorized issuance of USDR and EURR following a security breach in May.
The rating
On the financial side of the audit, the rating was upgraded because KPMG found that Tether International, S.A. de C.V.’s reserves exceeded its liabilities by $6.8 billion as of Dec. 31, 2025.
The new grade is the first to apply Bluechip’s expanded SMIDGE methodology, which incorporates Hacken’s technical-risk analysis alongside a financial and governance review. The approach combines an assessment of an issuer’s reserves with an examination of the code and administrative controls that govern the stablecoin’s issuance.
Bluechip and Hacken announced their partnership in August, saying the technical score would assess areas including smart-contract reliability, supply integrity, administrative key controls and off-chain infrastructure.
Bluechip had kept USDT at its D rating for years. The KPMG audit addresses one of the conditions Bluechip had previously set for an upgrade: a full-scope audit of Tether’s consolidated financial statements by an independent auditor.
With about $184.6 billion in outstanding supply, USDT is one of crypto’s most important sources of liquidity.
"Stablecoin ratings have always covered the financial side," said Benjamin Levit, CEO of Bluechip. "With Hacken’s technical data now integrated into our methodology, we can finally rate the full picture."
S&P Global Ratings downgraded USDT to the weakest possible score on its stablecoin stability scale in November due to concerns about its ability to maintain a price peg to the U.S. dollar, increased exposure to risky assets such as bitcoin, and ongoing gaps in reserve disclosure. Tether disagreed “strongly,” saying the rating agency applied a legacy framework that does not capture the nature, scale and macroeconomic importance of digitally native money.

Deputy Editor