$91 Billion in USDT Vulnerable to Single-Point Failure
Cybersecurity firm Hacken has identified vulnerabilities in the governance of USDT stablecoin on the TRON network, which could allow an attacker to gain control over $91 billion worth of tokens.
The assessment found that a 2-of-3 multisig setup is used for administrative transactions, where approval from two out of three designated key holders is required. However, this means that compromising two signing keys could potentially give an attacker control over privileged actions affecting the entire amount of USDT on TRON.
Hacken also discovered that the same set of signing keys are reused across multiple networks, including Ethereum, Avalanche, and Celo, which could have a ripple effect if compromised. Furthermore, there is no timelock for privileged USDT operations, allowing transactions to take effect immediately after approval.