Tether's $91 Billion Achilles Heel: Two Keys Could Control It All, While Stolen Bitcoin Keeps Moving
Security firm Hacken has given the stablecoin USDT a cybersecurity score of just 3.3 out of 10, warning that roughly $91.3 billion of USDT on the Tron network sits behind a contract whose administrative controls can be taken over by anyone holding two of three signing keys. There is no timelock and no way to cancel or reverse such an action once triggered. These controls can mint new tokens, freeze wallet addresses, and reassign ownership of the contract entirely.
Hacken found no evidence of an actual compromise, and the warning comes despite Tether's financial standing improving, with an audit recently confirming reserves exceed liabilities by $6.8 billion. However, the risk is not theoretical: a similar stablecoin lost 70% of its value in March after an attacker minted unauthorised tokens, and another platform disclosed unauthorised issuance in May.
Separately, the attacker behind July's Coldcard hardware wallet exploit has moved another $7.7 million in stolen bitcoin, in what is reportedly the third wave of activity involving the stolen funds. The original flaw allowed the attacker to generate wallet seeds with far weaker randomness than required, draining an estimated $38 million from about 500 wallets.