Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Hacken’s New Stablecoin Cybersecurity Methodology Enters Bluechip’s SMIDGE Framework, USD₮ Rating Upgraded From D to C

5 min read

Hacken-developed methodology assesses stablecoins on cybersecurity risk independently of reserves and financial backing, now implemented within Bluechip's independent ratings platform.

Today, Hacken and Bluechip announce that Hacken's stablecoin cybersecurity rating methodology is now integrated as a dedicated security layer inside Bluechip's SMIDGE stablecoin rating framework. The first assessment under the updated methodology upgrades the USD₮ (ticker $USDT) rating from D to C.

Bluechip rates stablecoins under the SMIDGE Framework, which covers Stability, Management, Implementation, Decentralization, Governance, and Externals. Under this partnership, Hacken's methodology adds greater technical cybersecurity depth to the framework, giving Bluechip's existing assessments a more detailed view of how a stablecoin's smart contracts, signing infrastructure, privileged controls, bridges, and other security mechanisms could withstand compromise.

Bluechip currently covers 30 stablecoins, rated from A+ to F. These ratings are displayed natively by data partners including RWA.xyz, Reserve, and Mt Pelerin, among others. Bluechip also organizes Bluechip26, the Crypto Safety Conference, presented by Raiffeisen Bank International (RBI) and Mastercard.

USD₮ carries roughly $184.6 billion in outstanding supply, more than any other stablecoin. At that scale, the security of its signing infrastructure is of material interest to the broader digital asset market.

USD₮ Assessment

Hacken assessed USD₮ across every blockchain holding at least 1% of its native supply — Tron, Ethereum, and Solana, together representing 98% of USD₮'s total native supply of roughly $184.6 billion.

In practical terms, the assessment found that some of USD₮'s most sensitive controls depend on a small number of signers, can be exercised without a delay period.

Key findings from the assessment:

  • Roughly half of USD₮'s outstanding supply is held on Tron, where privileged controls are secured through a 2-of-3 multisig. Tron holds about $91.3 billion in USD₮. The setup requires two of three designated key holders to approve a transaction. This means a compromise of two signing keys could give an attacker control over privileged actions affecting that supply.
  • The same signer account is reused across multiple chains. Ethereum, Avalanche and Celo share the same set of six signing keys under a 3-of-6 approval scheme. On Avalanche and Celo, those keys also control the ability to replace token code. This means a compromise of three signers could affect more than one deployment rather than being contained to a single chain.
  • There are no timelocks on privileged actions. Minting, freezing, and, where applicable, contract upgrades take effect as soon as the required signatures are collected. A timelock would introduce a delay between approval and execution, giving defenders an opportunity to detect and stop a malicious transaction.
  • No single-key takeover was identified. Administrative actions still require multiple signatures: two on Tron and Solana and three on Ethereum. Solana’s program is independently audited, although its mint and freeze authority remains behind the same 2-of-3 signing quorum.
  • Bridge infrastructure is secured by audited contracts and a bug bounty, but administrative control remains concentrated. Multiple security firms have reviewed the bridge contracts, and a bug bounty of up to $6 million is available. At the same time, privileged controls remain concentrated in multisignature infrastructure without timelocks.

The assessment credits USD₮'s reserve verification in full and penalizes the absence of any on-chain link between that verification and issuance. It found no on-chain issuance limit in the reviewed minting paths: once the required quorum authorizes a transaction, the reviewed contracts impose no additional limit on the amount that can be minted.

Why USD₮ Rating Was Upgraded

Two changes drive the upgrade from D to C. 

  • USD₮ issuer Tether International SA de CV completed a full financial audit with an unqualified opinion issued by KPMG US. This confirms that Tether’s accounts fairly represent the issuer’s financial statements in all material respects.
  • Hacken's new cybersecurity scoring methodology replaced Bluechip's previous treatment of technical risk with a documented, criterion-by-criterion assessment of USD₮'s architecture.

The upgrade does not resolve the key findings presented above. Concentration of control in a limited number of keys, and the speed at which those controls can be exercised, remain the binding constraints on USD₮'s technical risk profile.

How the Stablecoin Cybersecurity Methodology Works

Hacken's methodology assigns stablecoins to one of four structural classes according to their architecture and assesses them across six cybersecurity categories: smart contract security, supply integrity, operational security, oracle security, bridge and cross-chain infrastructure, and off-chain infrastructure security. Category weights vary by stablecoin class.

Each criterion is assessed against a fixed, documented rule, while defined “fatal states” can override the numerical score where an existential technical risk is identified.

For any given stablecoin, the same inputs produce the same score. Each class of stablecoin is measured against the risks specific to its own design. The six categories, in turn, map to the ways stablecoins present vulnerabilities, including compromised keys, manipulated oracles, exploited bridges, and failures in off-chain operations. 

USD₮ is the first stablecoin rated under this layer. Further assessments will be published on Bluechip in sequence so that ratings can be compared on the same basis rather than read in isolation.

“The stablecoin market has developed sophisticated ways to assess reserves, stability, and governance. Cybersecurity has not received the same level of standardized treatment. We are bringing that missing layer into the rating process, so the market can compare how resilient different stablecoin architectures are”— Dyma Budorin, CEO & Co-founder, Hacken
"Stablecoin ratings have always covered the financial side. With Hacken's technical data now integrated into our methodology, we can finally rate the full picture, including how secure the underlying architecture actually is. USD₮ is the first, and this is the new standard." - Benjamin Levit, CEO & Co-founder, Bluechip 

Why are stablecoins being risk-assessed now?

Recent stablecoin security incidents have highlighted risks that conventional assessments do not always capture. Resolv lost roughly $25 million in March 2026 after a privileged minting key was compromised, while regulated issuer StablR suffered unauthorized issuance following a security breach in May 2026. More broadly, stablecoin issuers face many of the same technical risks as other digital asset issuers, including weaknesses in access control, smart contract vulnerabilities, and dependencies on external infrastructure.

At the same time, stablecoins have reached roughly $322 billion in total supply, while Visa and Mastercard are expanding stablecoin settlement and infrastructure for financial institutions and payments. The GENIUS Act and MiCA have also established dedicated regulatory frameworks in the US and EU.

This combination of increasing adoption, regulatory scrutiny, and recurring security incidents is making technical risk assessment an increasingly important part of stablecoin risk management. Reserves and financial structure can confirm a stablecoin’s backing, but they do not, by themselves, show resilience to cybersecurity breaches. These risks, therefore, need to be assessed continuously and supported by publicly verifiable evidence that allows market participants to understand and compare the security of different stablecoin architectures.

About Hacken

Hacken is an end-to-end blockchain security & compliance partner for digital asset issuers. Unlike traditional providers, Hacken was born on blockchain, combining deep Web3 expertise with enterprise-grade quality, AI-powered offensive security, and globally recognized certifications.

Since 2017, Hacken has been trusted by 1,500 adopters, including the European Commission, ADGM, MetaMask, Ethereum Foundation, and Bybit, to secure the new digital frontier.

About Bluechip

Bluechip is the world's first and only crypto-native, independent stablecoin rating agency. Bluechip’s SMIDGE rating framework analyzes six economic factors and assigns letter-grade ratings (from F to A+) to identify the most reliable stablecoins. This framework evaluates financial risk, management quality, and now technical risk to present a clear and unbiased view of stablecoin safety. Bluechip's ratings and rating framework are publicly accessible, setting the standard for transparency in crypto markets.

Subscribe to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img