FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.7T +0.4%24h Vol $70.8B -36%Fear & Greed 63/100Alts Index 35/100
BTC.D 58.3% -0.1%Stable.D 9.9% -0.1%ETH.D 11.6% +0.1%Others.D 20.2% +0.1%
AI$0.3437+36.42%UAI$0.7955+18.86%ETHFI$0.7699+12.44%PROM$5.701+10.9%BTW$0.5531+10.54%WLFI$0.0570+8.42%SKY$0.0639+7.97%JST$0.1093+6.95%AKE$0.0153+5.37%MINA$0.1117+4.4%
APEPE$0.00000133-20.5%VVV$23.092-11.36%Q$0.0239-11.18%NEAR$2.386-10.76%LIT$4.332-9.35%MET$0.2387-9.07%MARSCOIN$0.1214-9.01%FF$0.1498-6.73%ENA$0.1425-6.1%CASHCAT$0.1765-5.88%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Hacken: Compromising Two Keys Could Give Control Over $91 Billion USDT

      • Hacken identified risks from the concentration of USDT admin control across three blockchains.
      • About $91 billion in USDT on the TRON network is controlled by a smart contract with two signing keys.
      • The contract has no timelock, cancellation mechanism, or any other way to roll back administrative changes.

      Cybersecurity firm Hacken conducted an assessment of the USDT stablecoin on the TRON, Ethereum, and Solana blockchains, which together account for 98% of its native supply. The total amount of USDT on these networks is about $184.6 billion.

      Hands-on analysis showed that some critical elements of stablecoin governance depend on a small number of signers and can be executed without any time delay.

      Almost Half of USDT Is on TRON

      About half of the total USDT supply is concentrated on the TRON network — roughly $91.3 billion.

      Privileged control over this amount is enforced via a 2-of-3 multisig setup. To execute an administrative transaction, approval is required from two of the three designated key holders.

      As a result, compromising two signing keys could potentially give an attacker control over privileged actions that affect this entire amount of USDT.

      At the same time, Hacken found no way to seize administrative control using only a single key.

      Keys Are Reused Across Multiple Networks

      Hacken also pointed out the reuse of the same set of signing keys across multiple networks. Ethereum, Avalanche, and Celo use the same set of six keys under a 3-of-6 approval scheme. On Avalanche and Celo, these keys additionally control the ability to replace the token’s code.

      Therefore, compromising three signers could potentially impact multiple USDT deployments at once, not just a single network.

      In addition, according to the assessment, there are no time delays for privileged USDT operations. Minting new tokens, freezing addresses, and, where applicable, upgrading smart contracts take effect immediately after the required number of signatures is collected.

      According to Hacken, a timelock would create a window between approval and execution of a transaction, during which defenders could detect and stop a potentially malicious operation.

      Issuance Has No Onchain Limits

      Hacken fully factored USDT’s proof of reserves into its assessment. At the same time, the company lowered the rating due to the lack of an onchain link between the reserve verification and the direct issuance of tokens.

      No onchain constraints on issuance volume were found in the audited stablecoin minting paths. After a transaction is authorized by the required signer quorum, the contracts do not set any additional limits on the amount of USDT that can be issued.

      Сообщение Hacken: Compromising Two Keys Could Give Control Over $91 Billion USDT появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud