The Sunday digest catches two security stories not yet covered here: a stablecoin key-management review that deserves more attention than it got, and a platform wind-down that closes out an incident from July.
Half of All USDT Sits Behind Two Signing Keys
A cybersecurity review by blockchain security firm Hacken, first reported by CoinDesk on September 4 and since corroborated by multiple outlets, gave USDT a cybersecurity score of 3.3 out of 10 — a verdict driven less by code defects than by administrative key arrangement.
According to the review, roughly $91.3 billion of USDT on Tron sits behind a contract whose administrative controls can be exercised by anyone holding two of three signing keys. Compromising those two keys would allow unauthorized actions up to and including minting large quantities of new USDT, with a potential blast radius covering about half of the token's supply. Hacken's assessment noted the arrangement carries no timelock, no cancellation window and no reversal mechanism.
The same week brought the opposite signal on the financial side: rating agency Bluechip raised Tether's corporate grade from D to C after an audit by KPMG US found its reserves exceeded liabilities by $6.8 billion. It was the first rating under Bluechip's expanded SMIDGE methodology, which folds Hacken's technical-risk analysis into the financial and governance review — meaning the upgrade and the 3.3/10 score are two halves of one picture: solvent reserves, concentrated keys.
The contrast is the entire argument for evaluating financial backing and key architecture together rather than separately. Tether has not publicly disputed the findings. Projects and issuers can be benchmarked continuously in TrustGrade's registry.
Cascade Winds Down After CLS Vault Exploit
Cascade, the 24/7 trading platform formerly known as Perennial, announced its shutdown on September 12 after five years of operation, directing users to Equilibria's claim portal to recover outstanding balances. The company had raised $15 million in 2025 from investors including Polychain, Variant and Coinbase Ventures.
The closure bookends a security incident the platform never fully moved past. On July 16, Cascade detected an exploit against its CLS vault: attackers manipulated prices in thinly traded markets, draining about $1.3 million in USDC from user funds. Trading and withdrawals were paused, and the team said it worked with security responders to recover most of the stolen funds, compensating users based on a July 15 snapshot.
The order of events in Cascade's own July disclosure is worth preserving: most orderbook orders in those thin markets had been created by the attackers themselves — the manipulation was manufactured before the drain. The wind-down statement cites prolonged operational challenges alongside the incident; Coin Edition and Bitcoin Ethereum News both report the shutdown followed milestone delays and limited community communication.
Users with remaining balances should follow only the claim instructions in Cascade's official announcements — wind-down periods are prime territory for impersonation scams.
Also Noted
The Symbiosis white-hat deadline expires today — our follow-up covers where recovery stands. And CoinGecko's 19-month security tally, analyzed in full here, quantifies the audit-gap problem this digest keeps running into: 88% of stolen funds came from platforms that had been audited.