$78 Million Lost to ‘Laundering Loophole’ in Tether Freezing Method Since 2017
By: cryptonews|2025/05/15 22:30:07
0
Share
There is “significant lag” between exchanges saying they’re going to freeze USDT held by malicious addresses and, well, actually doing it, according to a new report from AMLBot. AMLBot ’s report found that on-chain freezing enforcement of Tether’s USDT stablecoin has been sluggish. As a result, the anti-money laundering firm said, at least $78 million has been lost to bad actors on Ethereum and Tron since 2017. The “laundering loophole” is the result of Tether’s multi-signature contract set up, AMLBot explained in the report . First, a freeze request is sent on-chain which requires multiple signatures to approve before the freeze can be executed. As a result, a “window of opportunity” is created allowing illicit actors to move funds before their address is frozen. One example provided in the report showcases a 44 minute delay between the freeze request and confirmation on Tron. AMLBot claims that $49.6 million has been withdrawn by bad actors on the Tron network since 2017 as a result of the vulnerability. Wallets were able to make up to three transactions during the delay window with 4.88% of blacklisted wallets exploiting the lag on the network. Meanwhile on Ethereum, the firm found $28.5 million USDT withdrawn within the same timeframe. Totalling $78.1 million across the two chains. Security firm PeckShield reviewed the report and confirmed that the loophole exists. “It does not necessarily indicate a problem with the contract itself. Rather, it is an operational issue that creates a time window between when the blacklist transaction is submitted and when it is executed,” a PeckShield spokesperson told Decrypt . “Given the security-sensitive nature of the issue, improvements are definitely necessary.” Tether is the issuer of the largest stablecoin in crypto USDT, which aims to peg its price to the U.S. dollar. The company blacklists addresses from trading their products if they’re connected to illegal activity , such as wallets linked to the $1.4 billion Bybit hack earlier this year. Being blacklisted means the address can no longer move Tether issued assets, effectively making the tokens worthless. However, AMLBot believes malicious actors know of the aforementioned lag and are creating tools to exploit it. “Tools can be programmed to monitor the blockchain for specific contract interactions, such as submitTransaction() calls linked to freeze requests,” Slava Demchuk , CEO of AMLBot, told Decrypt . “The bots can alert wallet owners the moment a freeze is initiated but before it's enforced. Given the delay introduced by Tether’s multi-signature process, this provides a narrow but critical window for illicit actors to quickly move funds.” “While we haven’t directly observed the bots themselves, the on-chain behavior strongly suggests such automation is in play,” he added. PeckShield warned that the lag is inherent to how multi-sig accounts are designed to function. Simply, it takes time to have multiple people sign a transaction despite it being required in some cases to boost security. The firm suggested that Tether could bundle together the freeze request with the signatures into one transaction to eliminate the window. Tether did not respond to Decrypt ’s request for comment in time for publication, this article will be updated once received.
You may also like

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.

Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.

Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.

Huang Renxun's latest podcast transcript: The future of Nvidia, the development of embodied intelligence and agents, the explosion of inference demand, and the public relations crisis of artificial intelligence
The competition in the future is not just about whose model is larger or whose computing power is stronger, but also about who understands the industry better, who can embed AI more deeply into real processes, and who can organize these capabilities into a runnable and scalable system.

OKX Ventures Research Report: AI Agent Economic Infrastructure Research Report (Part 1)
The existing infrastructure is hostile to the Agent economy. Agents can think and act independently at the "capability level," but at the "economic level," they are still locked into infrastructure designed for humans.

The migration of settlement rights: B18 and the institutional starting point of on-chain banks
In the traditional system, banks decide the settlement; in the on-chain system, code begins to take over this responsibility.

From Tencent and Circle: Looking at the Simple and Difficult Questions of Investment
The AI narrative continues to ferment, but the recent performance of related stocks varies, with some in the midst of summer and others as if in winter.

The second half of stablecoins no longer belongs to the crypto circle
What Coinbase doesn't want, Mastercard is eager to buy.

Cursor "Shell" Kimi Controversy Reversed: From Copyright Infringement Allegations to Authorized Collaboration, China's Open Source Model Once Again Becomes a Global AI Foundation
Cursor was accused of being based on Kimi K2.5, which sparked controversy, and was later confirmed to be compliant through Fireworks AI due diligence.

The Real Reason Tokens Don't Sell: 90% of Crypto Projects Overlook Investor Relations
Provide an Investor Relations Best Practices Guide for Crypto Projects.

Is the income of pump.fun real, earning a million dollars a day despite the market downturn?
If it can really earn this much, what is the reason for the low price of $PUMP?

The real reason why tokens are not selling: 90% of crypto projects neglect investor relations
Investor Relations Practice Guide for Cryptocurrency Projects.

Who is the true winner of the "Tokenization" narrative?
Virtually everyone benefits, but the reason for the benefit, the timing, and the underlying logic are completely different.

Moss: The Era of AI-Traded by Anyone | Project Introduction
AI Trading Agent is rapidly growing its infrastructure.

Chip Smuggling Case Exposes Regulatory Loophole | Rewire News Evening Update
AI chips have become a strategic asset more sensitive than missiles
Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.
The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.
When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."
The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.
Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.
Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.