Tether’s corporate rating has been raised to C from D by Bluechip after a KPMG US financial audit, but a new cybersecurity review attached to that process gave USDT a much weaker score of 3.3 out of 10.
The review, conducted by blockchain security firm Hacken, said roughly $91.3 billion of USDT on Tron, about half of the token’s circulating supply, is governed by an administrative setup that could be taken over by anyone with two signing keys. Hacken said it found no sign that any key had been compromised and no evidence that any related incident has happened.
What the two-key risk means
According to Hacken’s assessment, the exposure does not involve user wallets directly. Instead, it centers on the smart contract administration behind USDT on Tron, including the ability to mint tokens, freeze addresses and transfer ownership of the contract itself.
Hacken said the design has no built-in delay, no cancellation process and no dependable method to reverse an ownership change once it is authorized. Smart contract auditor Seher Saylık said an attacker controlling two of the required keys could first move ownership to an address they control and shut out Tether’s legitimate signers.
Powers available after a compromise
From there, the report said, an attacker could act across the full deployment without accessing any individual account. Saylık said those powers could include minting USDT, pausing or resuming transfers, freezing addresses, deleting frozen balances, adding a transfer fee, or rerouting balances and transfers.
Because the authority sits at the contract level, the potential impact would extend across the token’s broader operation on the affected network rather than being limited to a handful of wallets. Hacken nevertheless stressed that its review uncovered no evidence of an actual breach.
Why the rating still improved
Despite the low cybersecurity score, Bluechip still upgraded Tether’s overall corporate grade. The change followed a financial audit by KPMG US, one of the Big Four accounting firms, and came under Bluechip’s new framework that combines financial analysis with Hacken’s technical review.
Tether is the first company evaluated under that updated system. Hacken said Bluechip’s existing B+ rating for Circle’s USDC should not be read as a direct technical comparison, because USDC was graded under Bluechip’s previous methodology before Hacken’s cybersecurity component was added. Tether did not immediately respond to a request for comment.
Cross-chain concerns and what comes next
Hacken said the same structural risk may not be limited to Tron. Saylık said Tether uses the same set of six signing keys across Ethereum, Avalanche and Celo, meaning a compromise involving keys used on one of those networks could also authorize a separate administrative action on Ethereum.
The review also noted that Tether’s established practice of freezing blacklisted addresses in law enforcement matters would not protect the system during a key breach. Blockchain adviser Ethan Whitcomb wrote in a November report that a two-key takeover could let an attacker reassign ownership permanently, stripping Tether of its own administrative control and disabling its ability to freeze funds. Hacken said it has not yet completed a comparable assessment of Circle’s USDC, making that a likely next point of reference for Bluechip’s newer review process.
Source: www.coindesk.com