Security Audit Flags 9 Vulnerabilities in $3.4B USDT0 Stablecoin Contracts
A DeFi security research team conducted a surface-level audit of USDT0, a cross-chain stablecoin with $3.45 billion in total value locked across Ethereum and Layer-2 networks including Arbitrum, Optimism, and zkSync. The audit, dated September 30, 2026, identified nine distinct attack vectors and assigned the protocol an overall risk score of 7.4 out of 10, categorized as High. The most critical findings include overly centralized admin privileges, an upgradeable proxy with an unprotected admin slot, and mint/burn functions whose access controls can be modified by the contract owner. Reviewers also flagged a governance timelock that can be bypassed via an executeImmediate() function, and cross-chain bridge signature handling vulnerable to replay attacks. While the codebase relies on audited OpenZeppelin libraries, researchers concluded that centralization of authority and bridge signature management represent the most exploitable weaknesses in the current deployment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in