Tether's $91B rests on two signatures
Hacken finds Tether's minting keys need just two of several signers, exposing $91B in USDT to a single breach.

Hacken's security review found that Tether's minting authority for USDT sits behind a multisignature setup requiring only two approvals. Compromise two signers and control of $91 billion in circulating supply follows.
The multisig setup
Tether uses a multisig wallet to authorize new USDT issuance, a standard design meant to spread trust across several keyholders. Hacken's finding is about the threshold, not the existence of multisig: a 2-of-N scheme means the bar for a breach is lower than the headline number of signers suggests.
That threshold matters more as the supply it protects keeps growing. USDT's market cap has roughly tripled since 2022, while the control mechanism behind it has not visibly changed in step.
- Tether receives Bluechip rating upgrade even as Hacken flags the key-threshold gap, per CoinDesk.
- USDT's circulating supply sits near $91 billion, per CoinDesk's reporting on the Hacken review.
- A 2-of-N multisig threshold is what Hacken identifies as the operative risk, not the total signer count.
- Tether's market cap has roughly tripled since 2022, according to public supply data referenced in the coverage.
What the rating upgrade obscures
The default read will pair "Bluechip rating upgrade" with "minor technical footnote" and move on. That pairing gets the risk backwards.
A rating upgrade measures reserve quality and disclosure practices. It says nothing about whether the keys controlling issuance can survive a targeted attack on two people instead of five or seven.
Reserve backing and key security are separate risk surfaces. Tether can hold full dollar reserves and still lose control of minting if the operational threshold protecting those reserves is low.
The number that matters here isn't $91 billion. It's the number two.
Every stablecoin issuer eventually has to answer how it protects its own signing infrastructure, because the reserves behind a token are only as good as the mechanism that decides how many tokens exist. A 2-of-N threshold answers that question with less margin than users likely assume when they see a rating upgrade attached to the same headline.
Centralized stablecoins already ask users to trust an issuer's solvency and its willingness to freeze or unfreeze funds on request. Hacken's finding adds a third trust assumption: that two out of some small set of people, or the systems protecting their keys, never get compromised at once.
The precedent for key compromise
Multisig breaches are not hypothetical. Crypto has already lost billions to exactly this failure mode.
The Ronin Bridge lost $625 million in 2022 after attackers compromised enough validator keys to clear the multisig threshold. Poly Network lost $611 million in 2021 to a contract logic flaw that let an attacker bypass multi-party controls entirely.
Neither of those systems backed anything close to $91 billion. Tether's exposure, by threshold design, is structurally similar and vastly larger in dollar terms.
The question isn't whether 2-of-N multisig can be breached. It's whether Tether's operational security around those two keys is materially better than Ronin's was before its breach.
Nothing in the Hacken review or CoinDesk's coverage answers that question with hard evidence. The finding establishes the threshold. It doesn't establish the defenses around it.
What to watch
- Whether Tether responds publicly with details on key custody, hardware security modules, or signer geographic distribution.
- Any move to raise the multisig threshold or add signers, which would be the clearest concrete fix.
- Whether other rating agencies or auditors incorporate key-threshold analysis into future Tether reviews, following Hacken's lead.
