A two-key breach could hand control of $91 billion in USDT to hackers, report finds

A cybersecurity report reveals that Tether's USDT stablecoin architecture relies on a two-key multisig system that could allow hackers to control the entire $91 billion supply if compromised. While Tether's corporate grade was recently upgraded following a financial audit, experts warn that the underlying technical security remains vulnerable due to a lack of on-chain safeguards.
Why it matters
The potential for a single point of failure in a massive stablecoin poses a significant systemic risk to the broader cryptocurrency market and global financial stability.
Even though the world's largest stablecoin received only 3.3 out of 10 on cybersecurity, rating company Bluechip raised issuer Tether's corporate grade to C from D, after a financial audit by KPMG US, one of the Big Four global auditing firms. The company is the first to be reviewed by Bluechip under a new system that pairs a financial review with analysis by Hacken. The review found no evidence that any key has been compromised or that any security incident has occurred.
The multisig does not hold user funds, it controls the USDT contract itself — the power to mint tokens, freeze addresses and reassign ownership — which is why a two-key compromise would let an attacker act across the entire deployment without touching any individual wallet.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in