Hacken said two compromised or colluding signers could take administrative control of a Tron USDT contract governing roughly $91.3 billion, with no built in delay or reversal window. The risk concerns issuer level contract administration—not direct access to individual users’ wallets—and could allow actions such as...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What vulnerability did Hacken identify in the multisignature administration of Tether’s USDT—particularly the roughly $91.3 billion circulat. Article summary: Hacken’s finding was a critical privileged-access risk, not evidence that USDT has already been hacked. Its concern was that compromise or collusion involving two of three administrators could give an attacker immediate,. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
A Hacken assessment identified a high-consequence privileged-access risk in the administration of USDT on Tron. The finding was not that USDT had been hacked: reporting on the assessment said there was no indication that the signing keys had been compromised or that a related breach had occurred. The concern is that control of two keys in a 2-of-3 administrative multisig could enable an attacker to take over a contract governing about $91.3 billion in Tron-based USDT, with no built-in timelock, cancellation window, or reliable rollback path. 18
24
The reported setup is a 2-of-3 multisignature arrangement for administrative actions. In such a design, any two authorized signers can approve a transaction. That protects against the loss or compromise of one key, but it also means that two compromised keys—or two malicious or coerced signers—meet the threshold needed to act.
For the affected Tron deployment, Hacken’s assessment said that valid approval from two signers could be used to seize administrative control without a required waiting period or a mechanism for other parties to cancel the action before it takes effect. The contract was reported to govern about half of USDT’s circulating supply at the time, approximately $91.3 billion. 18
22
This is a control-plane issue. It does not mean an attacker could automatically drain every holder’s wallet. Rather, it concerns the privileged functions used to administer the USDT smart contract itself. 22
36
Reporting on Hacken’s findings describes powerful contract-level permissions, including the ability to:
The severity comes from the combination of these powers and the lack of a mandatory delay. A timelock would create a period in which suspicious governance or administrative changes could be detected and potentially countered. Without one, a successful two-key takeover could take effect before users, exchanges, or the issuer’s security team had meaningful time to respond. 18
22
Hacken also reportedly found that six signing keys were reused across Ethereum, Avalanche, and Celo. Shared key material does not prove that those networks have the same multisig threshold or that a Tron incident would automatically compromise each deployment. But it creates correlated risk: a compromise of shared credentials could affect more than one chain instead of remaining isolated to a single environment. 41
This is why key reuse matters in security design. A system can have separate contracts on separate chains yet still rely on a common set of high-value credentials. That concentrates operational risk in the people, devices, processes, and recovery procedures that protect those keys.
No confirmed compromise was identified in the reporting provided. Hacken’s finding describes a potential attack path and a weak administrative-control design; it is not evidence of stolen keys, an unauthorized mint, a malicious ownership transfer, or a completed takeover. 24
The distinction matters. Calling the report a "$91.3 billion hack" would be inaccurate. The $91.3 billion figure refers to the approximate amount of Tron USDT governed by the contract, not reported losses.
Hacken’s low cybersecurity score reflects the potential impact and immediacy of the administrative-key risk. Two keys could potentially authorize control of a very large token deployment, while the reported design offered no built-in delay, cancellation process, or dependable reversal mechanism. 18
34
A cybersecurity score evaluates a different question from a reserve audit: whether the implementation and operational controls can withstand compromise. It is not, by itself, a statement that USDT reserves are missing or that the token has lost its peg.
Bluechip upgraded Tether’s corporate rating from D to C while Hacken’s technical assessment remained low. These conclusions are not necessarily contradictory because they address different layers of risk. Reporting said Bluechip’s revised methodology incorporated financial, governance, and cybersecurity factors, while the KPMG US audit related to Tether International’s 2025 financial statements. 18
24
KPMG US issued an unqualified opinion on those statements, and Tether said reserves exceeded liabilities by about $6.814 billion as of December 31, 2025. Reuters also reported that the audit itself was not made public. 1
Put simply:
Strong reported financial backing does not remove the risk that an attacker might exploit inadequate administrative controls. Conversely, a key-management weakness does not by itself show that reserves are absent.
Hacken’s score should not be read as a like-for-like technical comparison between USDT and Circle’s USDC. The reporting underlying this finding does not establish that Hacken issued an equivalent cybersecurity assessment of USDC. Without the same methodology applied to both systems, the scores cannot support a definitive relative-security ranking.
Different stablecoin assessments may also measure different things: reserve quality, legal structure, redemption processes, issuer governance, smart-contract privileges, or cybersecurity controls. A useful comparison requires knowing which of those dimensions a rating actually covers.
USDT is intended to be backed by issuer reserves. If a hostile administrator minted a material amount of tokens without corresponding assets entering the reserve pool, the number of outstanding redemption claims could exceed available backing. That mismatch could undermine confidence in the token’s ability to maintain its dollar peg.
The potential impact is amplified by scale. KPMG’s reported 2025 audit covered an issuer with roughly $180 billion in USDT liabilities, while the Tron contract alone was reported to govern about $91.3 billion. 1
18
In a stress scenario, newly minted and unbacked tokens could be sold into markets, pressure the peg, and lead trading venues and users to reassess USDT exposure. The direct outcome would depend on the incident response, the amount involved, market liquidity, and whether the issuer could quickly restore trustworthy control. But the core lesson is clear: for centralized stablecoins, reserve backing and secure administration are inseparable parts of confidence in the token.
Hacken’s report is best understood as a warning about concentrated administrative power. A 2-of-3 multisig can be a legitimate security control, but its risk rises sharply when it governs a very large deployment, has no timelock or recovery window, and relies on keys reused across networks.
There is no reported evidence of an active breach. Still, the assessment shows why stablecoin due diligence should extend beyond reserve disclosures: users and institutions also need to evaluate who controls upgrade and minting permissions, how signing keys are protected, whether critical actions are delayed, and how quickly a compromised system can be contained. 18
24
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Hacken said two compromised or colluding signers could take administrative control of a Tron USDT contract governing roughly $91.3 billion, with no built in delay or reversal window.
Hacken said two compromised or colluding signers could take administrative control of a Tron USDT contract governing roughly $91.3 billion, with no built in delay or reversal window. The risk concerns issuer level contract administration—not direct access to individual users’ wallets—and could allow actions such as changing ownership, minting tokens, freezing addresses, and changing transfer setti...
Tether’s reported $6.814 billion reserve surplus at December 31, 2025 and KPMG US’s unqualified audit opinion address financial statements, not whether multisig key management and contract controls are resilient.