A report found that a two-key breach could hand hackers control of $91 billion in USDT. The warning comes as a rating agency rolls out a framework that blends Wall Street financial auditing with Web3 code reviews.
The two-key scenario
The report describes a specific kind of attack. A two-key breach means both cryptographic keys that control a smart contract fall into the wrong hands. For USDT, that would give the attacker control of the entire supply — $91 billion.
The report frames it as a real risk, not a theoretical one. The keys in question are the ones that govern the stablecoin's smart contract. If both are compromised, there's nothing stopping the attacker from moving the funds.
A framework built on two tracks
The rating agency's new framework works on two tracks. The first is traditional financial auditing — the kind of work Wall Street firms do to verify that a company's assets match its claims. The second is Web3 code review, which examines the smart contract code that runs on-chain.
The framework is designed to evaluate both off-chain reserves and on-chain security. Off-chain reserves are the actual assets backing USDT. On-chain security is the code that governs how the token moves and who can control it.
Why both sides matter
A stablecoin can fail on either side. If the reserves aren't there, the token loses its peg. If the code is vulnerable, the token can be stolen. The two-key scenario the report describes is a code problem. The framework is designed to catch both kinds of problems.
The framework is new. Which projects get rated first — and whether the two-key risk gets patched — will determine how much it matters.




