$USDT Control Vulnerability Exposes $91 Billion in Tron Network
A critical flaw in the $USDT contract has been discovered by blockchain security firm Hacken. The issue lies in the use of a multisig setup that requires only two signing keys to be compromised, allowing an attacker to seize control of the entire deployment without any built-in delay or cancellation process.
The problem affects roughly half of all circulating $USDT on the Tron network, with a total value of around $91.3 billion. According to Seher Saylık, a smart contract auditor at Hacken, an attacker could change the contract owner to an address they control, lock out Tether's legitimate signers, and then mint new tokens, halt or resume transfers, freeze addresses, wipe frozen balances, impose a transfer fee, or redirect token balances and transfers.
Tether did not immediately respond to a request for comment. Hacken noted that it has not yet completed a comparable assessment of Circle's $USDC, which received a B+ rating from Bluechip under its earlier methodology.