Updated September 8, 2026. This assessment identifies a control risk, not an attack that has already happened.
USDT on Tron relies on privileged controls protected by a 2-of-3 multisig, according to Hacken’s new assessment integrated into Bluechip’s rating method. Two sufficient signatures can authorise sensitive functions on the network that carries roughly half of native USDT supply.
The finding matters, but it does not mean two keys can automatically withdraw every USDT in existence today. The useful questions are which administrative powers those keys control, how they are held and what defences limit a malicious or mistaken authorisation.
USDT on Tron and the 2-of-3 multisig finding
The primary Hacken assessment reviewed Tron, Ethereum and Solana, which together represented 98% of the analysed native supply, approximately $184.6 billion. On Tron, privileged controls were associated with a 2-of-3 configuration.
A multisig requires a minimum number of approvals from the available key set. One key is insufficient in a 2-of-3 arrangement; two reach the threshold. That is a genuine improvement over a single signer, although its tolerance for compromise remains limited.
Hacken also highlights the absence of an embedded delay for some sensitive actions. A timelock cannot prevent every abuse, but it may allow observers to detect a proposal, warn users and operators, or apply an emergency response before execution.
What an administrative key can control
Centralised tokens may include functions for issuance, freezing, upgrades or operational management. Keys do not necessarily share identical privileges, and every administrative action is not equivalent to freely transferring user balances. Impact depends on contract roles and off-chain procedures.
Privileged-key risk is separate from reserve risk. A contract can have a concentrated threshold while its backing assets remain sufficient, or robust technical controls alongside financial weakness. Our guide to stablecoin counterparty risk explains why those dimensions need separate evidence.
A lawful freeze requested by authorities and malicious control are also not the same event. The same technical capability may support several purposes. USDT holders should nevertheless understand that an issuer-administered token does not offer the administrative immutability of an asset with no issuer.
Why two keys do not automatically mean theft
Turning the weakness into an incident would require compromising or misusing the threshold, overcoming relevant organisational safeguards and submitting a valid action. On-chain configuration alone does not reveal physical custody, signer separation, hardware protection or internal monitoring.
Saying that two keys are sufficient therefore describes a concentration point rather than proving that one attacker can obtain them. The opposite mistake would be dismissing the architecture because no incident has been observed. An absence of exploitation is not an absence of exposure.
Bluechip’s overall USDT rating improved from D to C under the expanded assessment. The change shows that the report is not an absolute rejection. It combines financial and technical factors, recognising improvements while identifying controls that still warrant attention.
Tron’s threshold does not describe every USDT
Administrative arrangements differ across chains. Hacken reports a six-key set with a 3-of-6 threshold for Ethereum, Avalanche and Celo, while Solana uses a different technical model. Applying Tron’s 2-of-3 finding to every circulating USDT would be inaccurate.
Users should verify the network and official contract rather than relying on the ticker displayed by a wallet. Our USDT versus USDC comparison shows that issuer, reserves, freeze powers and network availability are separate parts of the decision.
Moving USDT from Tron to another chain also introduces exchange, bridge and execution risk. It is not an automatic remedy. The administrative threshold may change, but the user adds dependencies and costs that require their own assessment.
How privileged controls could be strengthened
A higher threshold and larger signer set can reduce the chance that a small number of credentials is sufficient, provided keys and operators are genuinely independent. Increasing the numbers without separating devices, people and organisations can create security theatre rather than resilience.
Timelocks, public monitoring, intelligible alerts and documentation of privileged functions make changes more observable. An emergency procedure is equally important: a delay only helps when someone detects the event and has a practical response available.
Code audits and periodic assessments do not replace operational transparency. A review captures the contract at a particular date, while later upgrades and key rotations change the exposure. Ratings therefore need a timestamp, scope and a clear account of what was not inspected.
What a holder can actually verify
An ordinary user cannot inspect the physical protection of every signer. They can identify network, official contract, issuer and custodian, avoid imitation tokens and unknown bridges, and recognise when lending or yield products add another layer of smart-contract and counterparty risk.
Operational balances require an understanding of freeze powers and the redemption policy of the service being used. Longer-term liquidity decisions should consider concentration by issuer, chain and custodian. A price near one dollar does not remove access or governance risk.
| Finding | Practical meaning |
|---|---|
| 2-of-3 multisig on Tron | Two approvals reach the privileged threshold |
| One key compromised | Not sufficient alone in the described setup |
| No timelock | Less on-chain reaction time |
| Rating moves D to C | Improvement with material risks remaining |
The USDT on Tron finding is not evidence of imminent collapse. It is a concentration of authority that warrants disclosure, stronger safeguards and continuing review. An informed holder combines issuer, network, contract and custody risk instead of treating a stable market price as proof that every layer is safe.
