About $91.3 billion of USDT, half of circulating supply, sits on Tron behind a contract whose administrative control comes down to two signing keys. That is the assessment by security firm Hacken, carried Monday by CoinDesk. A 2-of-3 multisig. No built-in delay. No cancellation window. No reliable undo. Hacken found no incident, no compromised key. We hold both sentences.

The vault does not hold user funds. It commands the contract: mint tokens, freeze addresses, reassign ownership. An attacker with two keys could first change the owner, lock out Tether’s legitimate signers, then mint, freeze, halt or resume transfers, wipe frozen balances, set a fee, redirect flows. Without touching an individual [wallet](/lexique#wallet). Seher Saylık, a Hacken auditor, told CoinDesk so over Telegram.

There is no built-in delay, cancellation process, or reliable way to undo the changes.Seher Saylık, Hacken, via CoinDesk, 7 September 2026

What 2-of-3 does, and what one key does not

A single key, on Tron, is not enough, writes Incrypted from the same review. On Ethereum, Avalanche and Celo, Hacken sees the same six keys, in a 3-of-6 scheme. A compromise on one side can sign on another. On Avalanche and Celo those keys can also replace the token code. Tron, Ethereum and Solana carry about $184.6 billion of USDT, 98% of native supply, still per Incrypted. Hacken has not yet published an equivalent on Circle’s USDC.

The contracts, Hacken says, have no automated proof of reserve and no hard cap. Once the quorum signs, the code mints the amount asked. That does not say the reserves do not exist. It says the code does not check them. Two files. We do not glue them. Holding the peg, as we already wrote of the on-chain dollar, does not erase the key architecture.

The C grade, the 3.3, two different rules

Tether is the first file under Bluechip’s new system, which pairs a financial review with Hacken’s cyber analysis. Bluechip lifts the corporate grade from D to C. Reason: the KPMG US audit as of 31 December 2025, reserves above liabilities by $6.8 billion. Hacken, on cyber, scores 3.3 out of 10. Leo Fan (Cysic.xyz) puts it, still in CoinDesk: the audit moved the needle. The architecture did not. Half the supply, about $91 billion on Tron, still sits behind two keys, with no timelock, and nothing on-chain, he says, seems to impede what those keys can mint tomorrow. Tether had not replied to CoinDesk at publication.

What this says for a reader

This is not a drainer on your signature. It is issuer risk. MiCA in Europe, which we told, does not change Tron’s keys. Banks tokenizing deposits play another game: the bank remains the bank. Here, two keys hold the contract. We say it. We do not turn it into a sell order. A holder of USDT does not have to « sell everything tonight ». They do have to know the risk is not their seed. It is the issuer.

  • Held: $91.3bn USDT on Tron (~half of supply), 2-of-3, no timelock or undo, admin contract not user funds, no incident found, 3-of-6 and six keys reused on ETH/Avalanche/Celo, code replacement possible on Avax/Celo, $184.6bn / 98% on Tron-ETH-Solana, Hacken 3.3/10, Bluechip D→C (first file under the new system), KPMG +$6.8bn at 31/12/2025, no USDC equivalent yet.
  • Not held: that an attack happened. That a retail wallet is emptied. A crash. That Tether is insolvent. Advice to sell or buy USDT.

Sources: CoinDesk / Hacken, Incrypted, Tether / KPMG statement. Nothing here is investment advice.