Hacken Sees Key Risk in $91 Billion USDT on Tron
Hacken points to the management of the USDT contract on Tron, where two signing keys are enough to control minting, freezing, and reassigning ownership. Bluechip raised Tether’s rating after a KPMG audit, but it still sees the technical risk.

Key Takeaways
- Hacken warns that about $91.3 billion in USDT on Tron could be taken over through a contract with two signing keys.
- The contract can mint tokens, freeze addresses, and reassign ownership, with no built-in delay or rollback option.
- Bluechip raised Tether’s rating after a KPMG audit, but Hacken says that does not remove the technical contract risk.
Hacken warns that about half of all USDT in circulation, worth around $91.3 billion (€78.6 billion) on Tron, is managed through a contract whose administrative control can be taken over with two signing keys. According to the security review, there is no built-in delay, no cancellation window, and no way to reverse a change. At the same time, Tether received a higher corporate rating from Bluechip after a financial audit by KPMG US, which shows that a stronger balance sheet is not automatically the same as a safer contract design.
What Hacken Saw
The core of the warning is not the reserves, but the way USDT on Tron is governed. The multisig does not control users’ wallets, but the USDT contract itself. That lets the system mint tokens, freeze addresses, and reassign ownership. If two keys are compromised, an attacker could therefore interfere with the entire system without touching individual wallets, according to Hacken.
Hacken also says the same risk could extend to Ethereum, Avalanche, and Celo, because Tether reuses the same six signing keys on those networks. The review found no sign that a key has already been compromised or that an incident has taken place. Still, auditor Seher Saylık stressed that there is no reliable way to undo a change once the keys have been used.
Rating Up, Risk Still There
Bluechip raised Tether’s corporate grade to C from D after a KPMG audit, with Tether International, S.A. de C.V. showing a reserve surplus of $6.8 billion (€5.9 billion) as of December 31, 2025. That was the first rating under Bluechip’s new SMIDGE system, which now combines financial analysis with Hacken’s technical risk review. Bluechip had kept Tether at D for years and saw the audit as an important condition for an upgrade.
Still, that higher rating does not change the technical side of the story. Hacken said USDT has no automatic proof-of-reserves checks and no limit on token creation. Once the signers approve a transaction, the contract can mint any amount without extra proof of bank deposits. That makes control of the keys especially sensitive, especially since Tether can also freeze or reassign addresses, according to the review.
Why This Matters for Europe
For European crypto investors, this matters because USDT is still one of the main sources of liquidity in the crypto market. If a stablecoin at this scale depends on a small number of keys, that says something about the operational risk behind a coin that is often used as a base layer for trading. That means the debate is not just about Tether, but also about the broader question of how strictly stablecoins should be judged from both a technical and financial angle.
Tether’s recent full audit by KPMG shows why the debate stays so sharp: financial transparency and technical control are not the same thing. Especially for a coin that is used this widely, regulators and traders want to be able to assess both sides at the same time.