Hacken is sounding the alarm on a major security risk in how USDT is managed on TRON. According to their analysis, control of the contract could be seized if just two signing keys are compromised. This contract currently manages around $91.3 billion USDT—about half of the total USDT supply, Hacken’s experts note.
What Hacken Found
The team discovered that a massive chunk of USDT is tied up in a contract with no built-in delay for changes, no cancellation window, and no solid rollback mechanism. That means any admin decision takes effect instantly, with zero buffer time—removing a layer of protection you’d usually expect for such huge sums.
How the Risk Works
This isn’t about users’ wallets. The issue is with the admin multisig that controls the USDT contract itself. This multisig setup lets admins mint new tokens, freeze addresses, or change contract ownership. If two signing keys are compromised, an attacker could take over these critical admin functions.
Why It Matters
With no delay or rollback options in place and this much value at stake, a key compromise could have massive consequences. The vulnerability specifically affects the admin controls for USDT on TRON—not user balances, but the contract’s core management parameters.
