started · updated
Tether USDT governance risk identified on Tron network
A security analysis by blockchain firm Hacken has identified a potential governance vulnerability in the Tether (USDT) smart contract on the Tron network. The analysis reveals that the contract operates under a 2-of-3 multisig structure, meaning any two of the three administrative signing keys can authorize major functions.
The report highlights a critical risk: the absence of a timelock or a cancellation mechanism for administrative changes. If two keys were compromised, an attacker could potentially seize control of the smart contract to mint new tokens, freeze specific addresses, or change contract ownership. While this does not imply an immediate threat to individual user wallets, it exposes the centralized management of the USDT supply on Tron, which accounts for approximately $91.3 billion of the total circulating supply.
Hacken also noted that Tether appears to reuse some signing keys across multiple networks, including Ethereum, Avalanche, and Celo, which could extend the impact of a potential breach. However, no evidence of actual key theft or security incidents has been found.
In a separate development, stablecoin rating agency Bluechip upgraded Tether’s corporate rating from D to C, following a financial audit by KPMG. The upgrade reflects improved reserve transparency and financial health, though critics note that the underlying technical governance risks identified by Hacken remain unchanged.