Hacken Scores Tether 3.3/10 as $91B in USDT Sits Behind Two Keys
Blockchain security firm Hacken found that $91.3 billion in USDT on Tron is governed by a 2-of-3 multisig with no timelock or reversal window. Bluechip upgraded Tether's corporate grade anyway. The two scores measure different things, and conflating them is the real risk.

Bluechip upgraded Tether's corporate grade on reserve strength. Hacken's cybersecurity review told a different story.
Key takeaways
- Blockchain security firm Hacken gave Tether a cybersecurity score of 3.3 out of 10, finding that roughly $91.3 billion in USDT on Tron is controlled by a 2-of-3 multisig with no timelock, no cancellation window, and no reversal mechanism.
- Rating agency Bluechip simultaneously upgraded Tether's corporate grade from D to C, driven by a KPMG audit showing reserves exceeded liabilities by $6.8 billion as of December 31, 2025. The two scores measure different things and should not be read together as a clean bill of health.
- Bitcoin has no equivalent attack surface. No admin key, no contract owner, no entity that can mint or freeze. The Tether finding is a concrete demonstration of what centralized ledger control looks like at $91 billion scale.
Blockchain security firm Hacken has found that approximately $91.3 billion in USDT circulating on the Tron network is governed by a smart contract controllable by anyone holding two of three signing keys, with no timelock, no cancellation window, and no reversal mechanism, per Hacken's assessment as first reported by CoinDesk. The finding came as part of Bluechip's new combined rating framework, which layers cybersecurity code review on top of traditional financial auditing. Bluechip upgraded Tether's corporate grade from D to C in the same review cycle, a split verdict that is already being misread as good news.
Two compromised keys would give an attacker the ability to mint new USDT, freeze or wipe addresses, reassign contract ownership, impose transfer fees, or redirect balances, all without touching any individual user wallet, per Hacken's assessment. Hacken found no evidence of compromised keys or an active security incident. The risk is architectural, not active. But architecture is permanent until someone changes it, and nothing in the current setup forces that change before an event occurs.
Tether did not respond to a request for comment.
What Two Keys Actually Control
The $91.3 billion Tron figure is not an abstraction. It represents roughly half of the approximately $183 billion in USDT circulating supply as of June 30, 2026, per BDO's Q2 2026 attestation published by Tether. An attacker who gains control of two of three signing keys does not need to touch reserves, does not need to compromise Tether's banking relationships, and does not need to defeat the KPMG audit. The on-chain contract gives those two keyholders direct, immediate, and irreversible control over the largest single pool of USDT in existence.
The exposure compounds further across chains. Hacken found that Tether reuses the same six signing keys across Ethereum, Avalanche, and Celo, per Hacken's assessment as reported by CoinDesk. A key compromise on any one of those chains can be leveraged against the others. The attack surface is not isolated to Tron.
Leo Fan, founder and CEO of Cysic.xyz and former lead on quantum resilience at Algorand, summarized the gap: "The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not." Fan added that $91 billion "still sits behind two keys with no timelock and nothing onchain seems to impede what those keys can mint tomorrow."
Tether is the first entity reviewed under Bluechip's combined financial and cybersecurity framework. Hacken has not yet completed a comparable assessment of Circle's USDC, which means USDC's existing Bluechip B+ rating cannot be directly compared against Tether's new scores on equivalent terms.
The Grade Split Is the Story
Bluechip's D-to-C upgrade was driven by a KPMG audit showing Tether's reserves exceeded liabilities by $6.8 billion as of December 31, 2025. That figure is the one circulating in headlines. What is less prominent: a separate BDO Q2 2026 attestation puts the current buffer at approximately $4.11 billion as of June 30, 2026, a roughly 40 percent compression in six months.
The reserve surplus is real. It is also shrinking and it addresses a completely separate question from the one Hacken's 3.3 score answers.
Reserve adequacy and on-chain security are orthogonal. A fully reserved stablecoin with a centralized admin key is still one social engineering attack, one insider threat, or one nation-state operation away from unlimited dilution. The KPMG opinion letter does not change what two signing keys can authorize on-chain. The market tends to blend these signals, and Bluechip's combined framework, however well-intentioned, creates the conditions for exactly that confusion. An upgrade from D to C reads as progress. Progress on the reserve side while the security score sits at 3.3 leaves the underlying security architecture unchanged.
This is the architecture that Tether has frozen $42.4 million in USDT from, per a lawsuit filed August 31, 2026 in the Southern District of New York alleging the freeze preceded any warrant by more than three months. The freeze capability is live, documented, and built into the same contract structure Hacken reviewed. The difference between a sanctioned freeze and an unauthorized one is the legitimacy of the keyholders, nothing more.
For context on how state-level actors approach this kind of infrastructure, sophisticated nation-state actors have already demonstrated the capacity to breach institutions most people assumed were hardened. A 2-of-3 multisig governing $91 billion with no timelock is a target, not just a vulnerability category.
The Falsifiable Thesis and What to Watch
The thesis is straightforward: Tether's rating upgrade is a confidence signal built on the wrong variable. Solvency is not security. A 3.3 out of 10 cybersecurity score on a contract governing $91 billion is not a footnote to a D-to-C upgrade; it is the primary finding.
That thesis becomes wrong if Tether publishes a verifiable, on-chain implementation of timelocks and a key-rotation scheme with adequate delay and genuine multi-party distribution, or if an independent third party demonstrates that the 2-of-3 signers are already hardware-isolated, geographically separated, and subject to a governance scheme that materially reduces single-event compromise probability. If the multisig signers are genuinely distributed across independent, airgapped institutions with documented incident response, the 3.3 score becomes a labeling problem rather than a systemic one. Until that evidence is public, the architecture stands as described.
What to watch: whether Bluechip publishes its full methodology for the new combined framework, whether Hacken releases the Tether assessment as a standalone public document, and whether a comparable USDC review produces a cybersecurity score that allows a direct comparison. The Bluechip USDT rating page is the live reference for the current combined grade.
Builders and operators running USDT settlement rails or holding USDT in treasury have a disclosed, quantified, unresolved single point of failure in their counterparty model. That belongs in the risk column, not the footnotes.
Sources
- Bluechip USDT Rating Page
- First reported by CoinDesk
Frequently Asked Questions
Yes, and this assessment confirms the mechanism is live. Tether's administrative keys can freeze individual addresses, wipe frozen balances, and halt transfers. That capability exists on Tron, Ethereum, Avalanche, and Celo. Tether has exercised it previously at law enforcement request.
Not automatically. Hacken found no evidence of compromised keys or an active incident. The risk is contingent on a key compromise event.
The relevant question is not whether reserves are adequate; it is what happens if two of three signers are socially engineered, compromised by an insider, or targeted by a nation-state actor. There is no built-in delay or reversal mechanism if that happens.
The Hacken assessment, per CoinDesk's reporting, confirms the reuse of six signing keys across Ethereum, Avalanche, and Celo, but does not explain the operational rationale. The consequence is clear regardless of reason: a compromise on one chain can be leveraged across the others.


