
tl;dr
A report from AMLBot highlights a delay in Tether's process of freezing USDT held by malicious addresses due to its multi-signature contract setup. This lag creates a window allowing bad actors to move funds before freeze enforcement, resulting in at least $78 million lost on Ethereum and Tron since...
A recent report from AMLBot exposes a significant delay in Tether's USDT freezing process due to its multi-signature contract setup. This delay creates a critical 44-minute window on networks like Ethereum and Tron, during which malicious actors have exploited the system to move illicit funds totaling $78.1 million since 2017.
Tether acknowledges this delay as a trade-off for enhanced security, highlighting that it has successfully frozen over $2.7 billion in USD₮ to date. The company disputes the characterization of this delay as a "loophole," emphasizing ongoing collaboration with law enforcement and faster freeze responses compared to competitors, notably in the wake of the Bybit hack.
Security firm PeckShield confirms the operational nature of the delay, explaining it as an inherent consequence of multi-signature account requirements, where multiple signatures must approve freeze requests. They suggest bundling freeze requests and signatures into a single transaction to close the exploitable window.
According to AMLBot's CEO, bots likely monitor freeze request activities on-chain and alert bad actors within the delay period, enabling swift movement of funds before enforcement takes place. Although direct bot activity has not been observed, transactional patterns strongly indicate automated exploitation.
Tether underscores USD₮ as one of the most traceable assets in the cryptocurrency sphere and reaffirms its commitment to working collaboratively with industry partners and law enforcement agencies to identify, freeze, and bring culprits to justice.
This situation highlights the tension between security protocols and operational efficiency in crypto asset control, posing important questions about the best approaches to prevent illicit fund movements while maintaining robust safeguarding measures.