The rating agency’s updated framework brings together traditional financial auditing and Web3 security analysis, allowing it to assess both an issuer’s off-chain reserves and the security of its on-chain infrastructure.
Around half of USDT’s circulating supply — approximately $91.3 billion on the Tron network — is controlled by a smart contract whose administrative authority can reportedly be taken over by anyone who gains access to two signing keys. According to blockchain security firm Hacken, the system has no built-in timelock, cancellation period or reliable mechanism for reversing such a change.
Despite identifying multiple cybersecurity concerns across the infrastructure supporting the world’s largest stablecoin, rating agency Bluechip upgraded Tether’s corporate rating to C from D. The upgrade followed a financial audit conducted by KPMG US, one of the Big Four accounting firms.
Tether is the first issuer assessed by Bluechip under its new methodology, which combines KPMG’s financial review with Hacken’s technical security analysis. Hacken said its assessment found no indication that any administrative key had been compromised or that a security breach had taken place.
The multisig arrangement does not directly hold customer funds. Instead, it controls the USDT smart contract and therefore has authority over critical functions such as token issuance, address freezing and ownership transfers. As a result, a compromise of two keys could give an attacker control over the entire deployment without requiring access to individual user wallets.
“There is no built-in delay, cancellation process, or reliable way to undo the changes,” Seher Saylık, a smart-contract auditor at Hacken, told CoinDesk via Telegram.
Tether had not immediately responded to a request for comment.
Hacken said it has not completed a similar technical assessment of Circle’s USDC. Bluechip’s B+ rating for USDC also cannot be directly compared with the new USDT assessment because the USDC grade was issued under Bluechip’s previous methodology, before Hacken’s cybersecurity analysis was incorporated.
Saylık explained that an attacker who obtained two valid signing keys could first transfer ownership of the USDT contract to an address under their control. That would remove Tether’s legitimate signers from control of the contract.
Once in control, an attacker could potentially mint new USDT, stop or restart transfers, freeze addresses, remove frozen balances, introduce transfer fees, or redirect token balances and transactions. None of those actions would require control of individual users’ wallets.
“The KPMG audit and the new scoring system, fortunately for Tether, moved the needle, but the architecture did not,” said Leo Fan, founder and CEO of Cysic.xyz and a former lead on quantum resilience at Algorand. He argued that roughly half of USDT’s supply, or about $91 billion on Tron, remains dependent on two keys without a timelock or an on-chain mechanism preventing those keys from authorizing large token issuance.
The potential exposure is not limited to Tron. Saylık said the same six signing keys are reused by Tether across Ethereum, Avalanche and Celo. A compromise involving keys used for Celo or Avalanche could therefore potentially be used to approve another administrative transaction on Ethereum.
Tether regularly freezes addresses that have been blacklisted in connection with law-enforcement investigations. However, security researchers say that function would not protect the system during a key compromise.
If an attacker gained control of two authorized keys, they could transfer ownership of the contract and potentially remove Tether’s administrative authority altogether. That could also prevent the issuer from carrying out functions such as freezing funds, according to blockchain adviser Ethan Whitcomb in a November report.
Hacken also confirmed Tether’s off-chain financial backing but noted that the reserves are not directly connected to the smart-contract execution process. USDT’s contracts do not automatically verify reserves through an on-chain proof-of-reserves mechanism, nor do they impose a hard limit on token issuance.
As a result, once the required signers approve a transaction, the contract can theoretically mint any amount of USDT without first verifying whether equivalent funds have been deposited in bank accounts.
The issue reflects a broader risk that has appeared elsewhere in the stablecoin sector. Resolv’s stablecoin lost about 70% of its value in March after an attacker minted tokens and extracted $25 million worth of ETH. StablR also reported unauthorized issuance of its USDR and EURR tokens following a security incident in May.
The Rating Upgrade
On the financial side, Tether received a higher rating after KPMG determined that Tether International, S.A. de C.V.’s reserves exceeded its liabilities by $6.8 billion as of December 31, 2025.
The new C grade is the first rating issued under Bluechip’s expanded SMIDGE methodology. The framework combines Hacken’s technical-risk assessment with evaluations of an issuer’s finances and governance.
The updated system examines both the reserves backing a stablecoin and the software, administrative controls and infrastructure responsible for issuing and managing its tokens.
Bluechip and Hacken announced their partnership in August. They said the technical component would examine areas such as smart-contract security, supply integrity, administrative key management and off-chain infrastructure.
Bluechip had maintained a D rating for USDT for several years. The KPMG audit satisfied one of the requirements the agency had previously identified for an upgrade: a comprehensive audit of Tether’s consolidated financial statements by an independent accounting firm.
With approximately $184.6 billion of USDT in circulation, the stablecoin remains one of the crypto market’s most important sources of liquidity.
“Stablecoin ratings have always covered the financial side,” said Benjamin Levit, CEO of Bluechip. He added that integrating Hacken’s technical data allows the agency to evaluate a broader picture of stablecoin risk.
S&P Global Ratings previously gave USDT its lowest possible score on its stablecoin stability scale in November. The agency cited concerns over Tether’s ability to maintain its dollar peg, its exposure to riskier assets such as Bitcoin and continued shortcomings in reserve disclosures.
Tether strongly disputed that assessment, arguing that S&P’s framework was outdated and failed to account for the scale, structure and growing macroeconomic importance of digital-native money.

More Stories
Altcoin Rally Fades as Bitcoin Pulls Back Over the Weekend
Bitcoin Faces $83K Resistance as Whales Turn to Net Selling
Friday Jobs Report Fails to Lift Fed Rate Hike Bets