Why Does The Two-Key Structure Matter?
About half of all circulating USDT, roughly $91.3 billion on the Tron network, is governed by a smart contract whose administrative control could be taken over by anyone who obtained two signing keys, according to an assessment by blockchain security firm Hacken.
The structure does not mean those keys directly hold users’ USDT. Instead, they control the contract itself, including the authority to mint tokens, freeze addresses and transfer contract ownership.
Hacken found no evidence that any signing key has been compromised and identified no security incident involving the controls. The concern is architectural: the contract lacks a built-in delay, cancellation window or dependable mechanism for reversing an unauthorized administrative transaction.
“There is no built-in delay, cancellation process, or reliable way to undo the changes,” said Seher Saylık, a smart contract auditor at Hacken.
According to Saylık, an attacker controlling the required keys could first transfer contract ownership to another address, potentially excluding Tether’s legitimate signers. From there, the attacker could mint USDT, freeze addresses, halt or restart transfers, remove frozen balances, introduce transfer fees or redirect balances and transfers.
No individual wallet compromise would be required.
Could The Risk Extend Beyond Tron?
Hacken said Tether also reuses the same six signing keys across Ethereum, Avalanche and Celo, creating a potential link between the administrative security of deployments on multiple networks.
A compromise involving keys used on Avalanche or Celo could therefore potentially authorize a separate administrative transaction on Ethereum, according to the assessment.
The existing freeze mechanism would not necessarily protect users in that scenario. Tether frequently uses its administrative powers to freeze addresses associated with law-enforcement actions, but an attacker who reassigned contract ownership could remove Tether’s ability to exercise those controls.
Another issue is the separation between Tether’s financial reserves and the code that issues USDT. Hacken found no automated proof-of-reserve mechanism inside the contracts and no hard cap restricting token creation.
That means the smart contract does not independently verify whether newly issued USDT is matched by assets held in reserve. Once the required signers authorize a transaction, the contract itself can mint the instructed amount.
Investor Takeaway
The finding does not show that Tether’s keys have been breached. It shows how much operational authority is concentrated in a small number of credentials. For investors, the distinction between reserve quality and smart-contract security matters because strong financial backing does not prevent unauthorized token issuance if administrative controls are compromised.
Why Did Bluechip Upgrade Tether Despite The Cybersecurity Findings?
Bluechip raised Tether’s corporate grade to C from D after applying a new methodology combining financial, governance and cybersecurity analysis.
The upgrade was supported by a KPMG US audit of Tether International, S.A. de C.V. KPMG found that reserves exceeded liabilities by $6.8 billion as of Dec. 31, 2025.
The audit addressed a long-running condition Bluechip had identified for improving Tether’s grade: completion of a full-scope audit of consolidated financial statements by an independent auditor.
The review was also the first conducted under Bluechip’s expanded SMIDGE methodology, which incorporates Hacken’s analysis of smart-contract reliability, supply integrity, administrative key controls and off-chain infrastructure.
“Stablecoin ratings have always covered the financial side,” said Benjamin Levit, CEO of Bluechip. “With Hacken’s technical data now integrated into our methodology, we can finally rate the full picture.”
Bluechip had previously maintained a D rating for USDT for several years. Its B+ rating for Circle’s USDC should not be treated as a direct technical comparison because that grade was assigned under the earlier system, before Hacken’s cybersecurity analysis was incorporated.
What Does The Finding Mean For Stablecoin Risk?
The assessment exposes a different category of stablecoin risk from the reserve questions that have traditionally dominated scrutiny of issuers.
USDT had about $184.6 billion in circulation, making it one of the most widely used sources of liquidity across crypto markets. A weakness in the administrative layer can therefore matter even when the assets backing the token are sufficient.
Other stablecoin projects have already suffered losses through unauthorized issuance. Resolv’s stablecoin dropped about 70% in March after an attacker minted tokens and extracted $25 million in ETH. StablR separately disclosed unauthorized issuance of USDR and EURR following a security breach in May.
S&P Global Ratings also cut USDT to the lowest grade on its stablecoin stability scale in November, citing concerns including Bitcoin exposure and reserve disclosure. Tether rejected that assessment, arguing that the framework failed to account properly for digitally native money.
The Hacken review adds another dimension to that debate. Tether’s financial position can improve while the operational risks embedded in the contracts remain unchanged, leaving investors to assess reserve strength and administrative security as separate parts of the same stablecoin risk profile.
