• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1

Nepal accepts crypto flood relief for the first time while keeping its crypto ban fully intact

09/08/2026
North Korean hackers

North Korea’s fake-worker scheme reached the US government, and its crypto pipeline just lost $212,700 to a federal judge

09/08/2026
Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

09/08/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1

Nepal accepts crypto flood relief for the first time while keeping its crypto ban fully intact

09/08/2026
North Korean hackers

North Korea’s fake-worker scheme reached the US government, and its crypto pipeline just lost $212,700 to a federal judge

09/08/2026
Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

09/08/2026
Tuesday, September 8, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

A security assessment has raised concerns over the control of about $91.3 billion in USDT on Tron, warning that the compromise of two signing keys could allow attackers to take control of key functions in Tether’s smart contract. 

by Victoria Philip
1 hour ago
in Crypto News
Reading Time: 3 mins read
0
Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk
Share on FacebookShare on Twitter

A security assessment by blockchain auditor Hacken has found that roughly $91.3 billion worth of USDT on the Tron network is governed by a 2-of-3 multisignature setup that could give an attacker control over minting, freezing and other contract functions if two of the three signing keys were compromised.

The report did not find evidence that Tether’s keys have been compromised or that hackers have stolen USDT.Instead, it states what could happen if two of the keys were ever obtained by an attacker.

Two keys could control critical USDT functions

Tether’s smart contract gives its administrators significant control over USDT.These functions include minting new tokens, freezing addresses and changing important settings within the contract.

Hacken said an attacker who obtained two of the three signing keys could change the contract’s ownership and gain control over these functions.

That could allow the attacker to mint new USDT, freeze addresses, clear frozen balances or introduce transfer fees without gaining access to individual users’ wallets.

The key point is that the multisignature wallet does not hold the $91.3 billion in USDT.Instead, it controls the smart contract that governs the tokens.

That distinction matters because compromising the keys would not mean directly stealing $91.3 billion from users. It could instead give an attacker control over the rules governing a huge amount of USDT.

Why the $91.3 billion figure matters

The amount involved is significant because USDT is the largest stablecoin in the cryptocurrency market.

On Tron, approximately $91.3 billion in USDT is linked to the contract examined by Hacken, representing about half of the stablecoin’s circulating supply.

The assessment also found that the contract has no built-in delay, cancellation process or reliable way to revoke an approved action once the required signatures have been provided.

This means that if two authorised keys were compromised, there may be limited time or technical mechanisms available to stop an attacker from using them.

The concern is therefore not that $91.3 billion is currently being stolen.It is that the control structure could create a very large impact if the required keys were ever compromised.

Tether’s security model relies on multiple keys

Tether already uses a multisignature system to reduce the risk of one person controlling the token issuance process.

Tether’s own documentation says multiple private authorization keys are required to create Tether Tokens. The company says this model is designed to prevent a single person from authorising tokens alone.

Tether also says its private keys control the ability to issue USDT, making the security of those keys a major priority.

The company says it reduces exposure by issuing tokens in batches rather than requiring its private keys to be used every time a customer requests USDT.

What happens if the number of keys required to take control of the contract is itself too small?

The same keys may create a wider risk. Hacken also identified another concern involving the use of signing keys across different blockchains.

According to the assessment, Tether reuses the same six signing keys across Ethereum, Avalanche and Celo. That creates a potential cross-chain risk.

If the same keys were compromised, the consequences could extend beyond one blockchain rather than being limited to the Tron network.

This does not mean that all of these networks have been compromised.There is currently no evidence that Tether’s keys have been stolen.

But it means that a single successful attack against the relevant signing infrastructure could potentially have consequences across multiple networks.

USDT can be changed by its administrators

The concerns also shows how much control Tether retains over USDT even though the token operates on public block chain.

Tether’s own documentation says administrators can perform functions such as minting, freezing, unfreezing, revoking and burning tokens.

Tether also says it can, in certain circumstances, seize and destroy tokens in response to requests from governments, law enforcement agencies or other authorities.

These controls give Tether the ability to respond to threats and comply with legal demands.

But they also mean that the security of the administrative keys is critical to the wider USDT ecosystem. No evidence of an active attack

Hacken did not report that attackers had obtained Tether’s keys.There is also no indication that users’ USDT wallets have been compromised as a result of the findings.Instead, the assessment identifies a potential weakness in the way control over the smart contract is structured.

Hacken gave the USDT smart contract a cybersecurity score of 3.3 out of 10 and also raised concerns about the absence of an automatic reserve check and a limit on the number of tokens that can be minted.

That does not mean USDT is currently unsafe.It means that the consequences of a successful compromise could be unusually large.

What the vulnerability means for USDT

The bigger question is not whether $91.3 billion in USDT is currently at risk of being stolen. It is how much damage could be caused if an attacker gained control of the keys responsible for administering the token.

If unauthorised USDT were created, markets would have to determine whether those tokens were legitimate.

A large amount of unbacked or unauthorised USDT entering the market could damage confidence in the stablecoin and potentially create wider disruption across exchanges and decentralised finance platforms.

For now, however, USDT continues to operate normally and there is no evidence of a successful attack.

Tags: $91.3 billion USDT2-of-3 multisigBlockchain Securitycrypto cybersecuritycrypto vulnerabilityCryptocurrency NewsHackenmultisig key riskprivate key securitysmart contract riskstablecoin riskstablecoin securitytetherTether securityTronTRON USDTusdtUSDT security risk
Share198Tweet124
Victoria Philip

Victoria Philip

Victoria Philip is a journalist, writer, and storyteller with a strong interest in technology, business and the changing world around us. Her work combines research, observation, and thoughtful analysis to explore ideas beyond the surface. She is particularly interested in opinion writing that challenges assumptions, examines everyday realities, and gives readers a fresh perspective on issues that matter.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1

Nepal accepts crypto flood relief for the first time while keeping its crypto ban fully intact

09/08/2026
North Korean hackers

North Korea’s fake-worker scheme reached the US government, and its crypto pipeline just lost $212,700 to a federal judge

09/08/2026
Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

Hacken finds Tron’s $91.3 billion USDT exposed to 2-of-3 multisig key risk

09/08/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.