San Francisco Daily 360

collapse
Home / Daily News Analysis / A two-key breach could hand control of $91 billion in USDT to hackers, report finds

A two-key breach could hand control of $91 billion in USDT to hackers, report finds

Sep 10, 2026  Twila Rosenbaum 48 views
A two-key breach could hand control of $91 billion in USDT to hackers, report finds

Key facts

  • Blockchain security firm Hacken found that about $91.3 billion of USDT on Tron is controlled by a 2-of-3 multisig wallet.
  • The contract lacks built-in delays or timelocks, meaning two signing keys could authorize irreversible administrative actions.
  • An attacker who obtained two keys could potentially mint new tokens, freeze addresses, or reassign ownership.
  • Hacken gave USDT a cybersecurity score of 3.3 out of 10, even though it found no evidence of compromised keys or an active security incident.
  • Bluechip raised Tether's corporate grade from D to C after a KPMG audit found reserves exceeded liabilities by $6.8 billion.
  • Hacken warned that reused signing keys could extend administrative risk across Ethereum, Avalanche, and Celo.

A new security review has put a spotlight on one of the most consequential pieces of infrastructure in crypto: the administrative control of Tether's USDT, the largest stablecoin by market value. According to the review, about $91.3 billion of USDT on the Tron network is controlled by a contract that uses a 2-of-3 multisignature wallet. That setup means three signing keys exist, and any two of them can authorize certain administrative actions. The same review found that half of all circulating USDT depends on a 2-of-3 multisig wallet without built-in delays or timelocks.

The finding matters because the powers attached to those keys are not limited to routine maintenance. In a worst-case scenario, an attacker who obtained two of the three keys could mint new USDT, freeze addresses, or reassign ownership of the contract. Because the contract reportedly lacks a timelock or delay mechanism, those actions could be executed without a waiting period and without an automatic reversal path. That would leave little time for exchanges, issuers, or the broader market to react before the damage was done.

What a 2-of-3 multisig means

A multisignature wallet requires more than one private key to approve a transaction or administrative action. In a 2-of-3 arrangement, three keys are created, and any two can combine to authorize an action. This is a common security model because it avoids a single point of failure: one lost or compromised key is not enough to move funds or change control. But the model is only as strong as its threshold and its operational safeguards. A 2-of-3 setup is less resilient than a 3-of-5 or 4-of-7 arrangement, especially when the keys are held by a small number of people or generated in a way that creates shared risk.

The review did not say that the keys had been compromised. It also did not report an active security incident. Instead, it highlighted a structural risk: the contract's administrative controls could be seized with two keys, and there is no built-in delay to allow for intervention. That distinction is important. A theoretical vulnerability is not the same as an active exploit, but in a system that secures tens of billions of dollars, even a theoretical path to control can have market-wide implications.

Why Tron is central to USDT liquidity

Tron has become a dominant network for USDT transfers. Its low fees and high throughput have made it a preferred rail for users moving dollar-pegged tokens, especially in regions where access to traditional banking is limited or expensive. A large share of USDT activity occurs on Tron, and the network's TRC-20 version of USDT is widely integrated into exchanges, payment services, and decentralized finance protocols. That concentration is a strength for efficiency, but it also means that a security issue affecting the Tron contract could ripple far beyond one blockchain.

If an attacker could mint USDT at will, they could dump new tokens into the market, disrupt pricing, and force exchanges and liquidity providers to react under pressure. If they could freeze addresses, they could lock users out of funds. If they could reassign ownership, they could take control of the contract's administrative functions. Each of those outcomes would test the stablecoin's peg, the solvency of intermediaries, and the confidence of users who rely on USDT as a dollar substitute.

Financial strength versus technical security

The review's cybersecurity score for USDT was 3.3 out of 10, a low rating that suggests significant concerns about the contract's defensive design. Yet the same period brought a more positive assessment of Tether's financial position. A separate rating action raised Tether's corporate grade from D to C after an audit found that its reserves exceeded liabilities by $6.8 billion. The rating agency's framework combines Wall Street-style financial auditing with Web3 code reviews, evaluating both off-chain reserves and on-chain security.

Those two signals measure different things. The financial audit speaks to solvency: whether the assets backing USDT are sufficient to cover redemptions. The cybersecurity score speaks to operational and technical risk: whether the code, keys, and governance processes can withstand attack. A stablecoin can be well collateralized and still carry dangerous technical vulnerabilities. Conversely, a technically robust contract can still face questions about reserves, transparency, or regulatory compliance. For users and institutions, the lesson is that neither metric alone tells the full story.

Cross-chain key reuse raises the stakes

The review also warned that reused signing keys could extend administrative risks across Ethereum, Avalanche, and Celo. Key reuse is a common but dangerous practice in security engineering. If the same key material or key-generation process is used across multiple deployments, a compromise in one environment can undermine the others. In the context of stablecoin administration, that could mean a single breach has implications for multiple blockchain networks, not just the one where the initial vulnerability was found.

Even without evidence of compromise, the possibility of cross-chain exposure changes the risk calculus. Security teams would need to verify that keys are unique, stored separately, and rotated according to strict procedures. They would also need to monitor for unauthorized signing attempts across all relevant chains. If keys are shared or generated with similar entropy, an attacker who gains access to one could potentially move laterally. That is why auditors often focus not only on the smart contract code but also on the human and operational processes that surround key management.

Centralization trade-offs in stablecoin design

USDT is a centralized stablecoin, and its administrative powers are a deliberate design choice. Tether can freeze addresses, mint new tokens, and burn tokens as part of its role as issuer. Those powers are used for compliance, recovery, and market operations. They can help law enforcement respond to theft or fraud, and they can allow the issuer to maintain the peg during periods of stress. But the same powers create a central point of failure. If control of those powers is lost, the consequences can be systemic.

Timelocks and delays are one mitigation. A timelock would not prevent a malicious action forever, but it would create a window for defenders to detect the attempt and coordinate a response. Exchanges could halt deposits, users could exit, and the issuer could try to revoke or replace keys. A delay also gives security teams time to investigate whether a signing request is legitimate. The review's finding that the contract lacks built-in delays or timelocks is therefore significant: it removes a layer of defense that could otherwise reduce the impact of a key compromise.

What happens if two keys fall into the wrong hands

If two keys were compromised, the attacker's options would depend on the exact permissions attached to the multisig. In many stablecoin contracts, administrative functions include minting new supply, freezing or unfreezing accounts, and transferring contract ownership. An attacker could mint a large amount of USDT and sell it across exchanges, pressuring the peg. They could freeze addresses to lock out competitors or extort users. They could reassign ownership to a new address, potentially locking out the legitimate issuer. Without a reversal mechanism, undoing those actions could require a network-level intervention or a coordinated migration to a new contract.

The market impact would likely be immediate. Traders would question whether all USDT on Tron were fully backed, whether the attacker's minted tokens were valid, and whether exchanges would honor withdrawals. Liquidity providers might widen spreads or pause trading. DeFi protocols that accept USDT as collateral could face cascading liquidations if the token's value wobbled. Payment processors and remittance services that depend on Tron's low fees could be disrupted. The $91.3 billion figure captures the direct exposure on Tron, but the broader stablecoin economy could feel the shock.

No evidence of compromise, but warnings remain

The review found no evidence of compromised keys or a security incident. That is a crucial caveat. The report is a risk assessment, not a disclosure of a breach. It points to a vulnerability that could be exploited if certain conditions were met. The absence of an active incident does not mean the risk is hypothetical; it means the system has not yet failed in that specific way. Security experts often distinguish between a flaw and an exploit, and this finding sits on the flaw side of the line.

The warning about reused signing keys adds another layer. If keys are reused across Ethereum, Avalanche, and Celo, the administrative risk is not confined to Tron. Each additional chain expands the attack surface and the number of systems that must be secured. It also complicates incident response, because defenders would need to determine which deployments were affected and whether the same keys could authorize actions elsewhere. For an asset with the liquidity and integration of USDT, that kind of cross-chain uncertainty can be as damaging as a confirmed breach.

The report does not allege that such a breach has occurred. It does, however, identify a structural weakness that could turn a key-management failure into a market-wide event, and it warns that reused signing keys could carry that risk across Ethereum, Avalanche, and Celo.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy