Security review flags two-key control risk over roughly $91B of Tron USDT
Hacken says a 2-of-3 multisig can administer about half of circulating USDT on Tron without a built-in timelock; no keys were reported compromised, and the finding is a governance risk rather than a confirmed exploit.
By The Third AnglePublished 4 min read
Administrative keys can create a different risk profile from the reserves backing a stablecoin. Photo: Unsplash · Unsplash License
A concentration risk in contract administration
A security review by blockchain auditor Hacken says roughly half of circulating USDT on Tron—about $91 billion at the time of the analysis—depends on a 2-of-3 multisig arrangement for smart-contract administration. CoinDesk reported that the contract lacks a built-in timelock, cancellation process or reliable revocation mechanism for changes to administrator control.
The finding does not say that Tether’s reserves are missing or that two keys have been stolen. It describes what could happen if two authorized signing keys were compromised or colluded: an attacker could potentially change contract authority and then use administrative functions such as minting, freezing or altering balances, subject to the contract’s implementation and other controls.
The crucial distinction is a control risk is not a confirmed breach. The review, as reported, found no evidence that the signing keys had been compromised. The dollar figure is an exposure estimate tied to the amount of USDT issued on Tron, not money that is currently at risk of disappearing in a live attack.
Why timelocks and separation matter
A timelock can create a delay between an administrative decision and its execution, giving monitors time to detect an unauthorized change and coordinate a response. A cancellation or revocation path can add another layer of defense. Without those mechanisms, the security model relies more heavily on key custody, signer separation, monitoring and incident response.
The review also highlights a governance issue that is separate from Tether’s reserve attestations. A company can hold sufficient assets to back a stablecoin while still facing questions about who can change the token contract and how quickly those changes can take effect.
Readers should watch Tether’s response and any contract-control changes. Useful evidence would include an updated signer architecture, a timelock or emergency-cancel design, independent code review and clear documentation of which functions remain available to administrators.
Until then, the defensible takeaway is narrow: Hacken identified a concentration and recovery-time concern in the administrative controls for Tron-based USDT, while the available reporting does not show a live compromise. The finding is relevant to stablecoin infrastructure and operational security, but it is not proof that USDT reserves are impaired or that holders face an immediate confirmed loss.