$91 Billion USDT at Risk: Critical Vulnerability Discovered in Management
The USDT stablecoin's management has been identified as having a critical risk. Hacken, a smart contract auditor, discovered that approximately $91.3 billion in USDT on the TRON network is managed by a contract vulnerable to control if two signature keys are compromised.
According to an assessment by Hacken, about half of the stablecoin's market supply is tied to a contract without built-in delay, cancellation window, or reliable rollback mechanism. This risk is associated with an administrative multisig that manages the USDT contract itself, allowing for token issuance, address freezing, and contract ownership reassignment.
Seher Saylik, Hacken smart contract auditor, stated that if two keys are compromised, an attacker could change the owner to a controlled address, depriving Tether of management access. In such a scenario, the attacker could also issue new USDT, halt or resume transfers, impose fees, and alter other administrative parameters.
Hacken emphasized that no signs of key compromise or incidents have been detected, but noted that Tether uses the same six keys across Ethereum, Avalanche, and Celo, meaning that a compromise in one network could potentially affect other stablecoin deployments.