Industry News

Tether's $91 Billion Achilles Heel: Two Keys Could Control It All, While Stolen Bitcoin Keeps Moving

CryptoTicker · 7 Sept 2026
Key Takeaway Businesses holding or accepting stablecoins should understand who controls the underlying admin keys, and treat concentrated key management as a real operational risk, not just a technical detail.

Security firm Hacken has given the stablecoin USDT a cybersecurity score of just 3.3 out of 10, warning that roughly $91.3 billion of USDT on the Tron network sits behind a contract whose administrative controls can be taken over by anyone holding two of three signing keys. There is no timelock and no way to cancel or reverse such an action once triggered. These controls can mint new tokens, freeze wallet addresses, and reassign ownership of the contract entirely.

Hacken found no evidence of an actual compromise, and the warning comes despite Tether's financial standing improving, with an audit recently confirming reserves exceed liabilities by $6.8 billion. However, the risk is not theoretical: a similar stablecoin lost 70% of its value in March after an attacker minted unauthorised tokens, and another platform disclosed unauthorised issuance in May.

Separately, the attacker behind July's Coldcard hardware wallet exploit has moved another $7.7 million in stolen bitcoin, in what is reportedly the third wave of activity involving the stolen funds. The original flaw allowed the attacker to generate wallet seeds with far weaker randomness than required, draining an estimated $38 million from about 500 wallets.

cryptocurrency stablecoin-security key-management wallet-exploit Tether

Summarised by CISO AI from CryptoTicker. We link back to every original so you can read it yourself.