NewsCryptoHacken Flags Two-Key Breach Risk to USDT Privileged Controls

Hacken Flags Two-Key Breach Risk to USDT Privileged Controls

Author: DefiLiban·

Key Takeaways

  • An unconfirmed Hacken report flags a two-key breach risk tied to USDT's privileged controls over minting, freezing, and blacklisting, but the underlying report details were not independently retrieved.
  • Bluechip's assessment states one multi-sig holds unbounded mint, freeze, and blacklist capability for Tether, with no timelock on any privileged action across deployments.
  • USDT, the largest stablecoin by market capitalization, traded within a fraction of a cent of its $1 peg, showing no market dislocation linked to the report.
  • The GENIUS Act, enacted July 18, 2025, directs regulators to set operational and IT risk standards for payment stablecoin issuers, though it sets no multi-sig threshold and alleges no Tether violation.
  • Bluechip's USDT page shows a C grade with a last-change date of September 3, 2026, but whether this represents an upgrade from a prior grade remains unconfirmed.
Hacken Flags Two-Key Breach Risk to USDT Privileged Controls

A Hacken report has flagged a two-key breach risk affecting USDT's controls, according to unconfirmed reports, raising questions about how much of Tether's privileged authority rests behind a small set of signing keys. The claim concerns the control layer that governs minting, freezing, and blacklisting on USDT — not any confirmed compromise, unauthorized mint, or loss of user funds.

Key points:

  • Hacken flags a two-key risk tied to USDT's privileged controls.
  • The concern involves USDT mint, freeze, and blacklist authority.
  • The supplied context establishes neither a confirmed breach nor its technical scope.

What Hacken flags about USDT controls

The two-key breach claim reaches this report through unconfirmed reporting and is available only as a headline; the original Hacken report, the exact key threshold, the signer total, and the affected contracts were not independently retrieved. It should be treated as a reported control-security risk, not as evidence of an incident. For related coverage, see Router Protocol to shut down, burn 303 million ROUTE tokens.

What is independently documented is the shape of USDT's privileged tooling. Bluechip's published USDT assessment states that one multi-sig holds unbounded mint, freeze, or blacklist capability for Tether, and that no deployment carries a timelock on any privileged action, according to Bluechip's rating page. The assessment does not specify the signer threshold. For related coverage, see Harmony Wants to Shut Down Its Blockchain Over AI Threats.

That concentration matters because freeze and blacklist functions are not incidental to USDT's design: they are the compliance levers regulators and law enforcement can reach, which is precisely why their custody arrangement — how many keys guard them and who holds them — sits at the intersection of security engineering and policy.

Bluechip's rating context stems from a technical-risk partnership. In its August 25, 2026 announcement, Bluechip said it is integrating Hacken's scoring into the Implementation factor of its SMIDGE framework, with Hacken's methodology spanning smart contract reliability, supply integrity, operational security, oracle and bridge security, and off-chain infrastructure. That framing positions concentrated signer authority as a scored technical risk rather than a solvency question. For related coverage, see StonkFun Draws Solana Trading to Raydium and Jupiter.

Bluechip stated in its August 25, 2026 partnership announcement: "Stablecoins can be fully backed and still depeg. Adequate reserves of high quality assets are necessary, but far from sufficient to build a safe stablecoin."

What the two-key finding means

Because the report itself was not retrieved, the mechanism behind a two-key figure cannot be mapped to a specific multi-sig threshold or to a defined set of permissions. Two keys should not be read as an m-of-n quorum, nor assumed to unlock mint, freeze, and blacklist simultaneously, until report evidence establishes the key arrangement and the functions those keys control.

What the reported risk could mean for USDT

USDT remained the largest dollar-pegged stablecoin by market capitalization and traded within a fraction of a cent of its $1 peg in the research snapshot, showing no market dislocation tied to the report.

Conditions that determine potential impact

Any impact assessment depends on which controls the flagged keys can actually exercise and under what preconditions. Bluechip's finding that USDT's mint path references no backing and that no on-chain reserve feed exists is an attributed governance observation, not evidence that unauthorized minting occurred. Absent such evidence, a hypothetical key-compromise scenario remains separate from claims of freezing, reserve losses, a depeg, or user-fund exposure.

The concentration also carries regulatory weight. The GENIUS Act, enacted July 18, 2025 as Public Law 119-27, directs regulators to set operational, compliance, and information-technology risk standards for permitted payment stablecoin issuers under section 4(a)(4)(A)(iv), and section 2(16) contemplates lawful orders to seize, freeze, burn, or prevent transfers, per the enacted statute. That makes both control availability and control security policy-relevant, though the law establishes no multi-sig threshold and no Tether violation.

What remains to be verified

The core two-key claim is unverified. Assessing it requires the report's date and scope, its exact wording, the key custody arrangement, the chain and contracts tested, and the permissions the keys control — none of which the supplied evidence establishes. This mirrors the sourcing gap seen in other control-security stories, such as the reported pause of the Liquid Network after a large Bitcoin withdrawal, where the mechanism mattered more than the headline figure. What to watch next is whether Hacken or Tether publishes the underlying report detail — signer counts, thresholds, and affected functions — and whether any remediation, such as added timelocks or a restructured quorum, follows.

Bluechip's USDT page shows a C grade with a last-change date of September 3, 2026; the page alone does not confirm the prior grade or that the change was an upgrade, and reports describing it as an upgrade remain unconfirmed. The GENIUS Act's effective-date trigger under section 20 — the earlier of 18 months after enactment or 120 days after final regulations — was not shown to have occurred. No Tether response, mitigation, or remediation status was retrieved for this brief; that absence does not establish that none exists.