$78 Million Lost to ‘Laundering Loophole’ in Tether Freezing Method Since 2017
By: bitcoin ethereum news|2025/05/16 12:00:14
0
Share
In brief A delay between the request to freeze an address and its on-chain execution for Tether’s USDT stablecoin was found by blockchain forensics firm AMLBot. Tether blacklists addresses connected to illegal activity, freezing the wallets from moving assets issued by the company. As a result of the freeze delay, AMLBot’s report claims, malicious actors got away with more than $78 million on Ethereum and Tron since 2017. There is “significant lag” between exchanges saying they’re going to freeze USDT held by malicious addresses and, well, actually doing it, according to a new report from AMLBot. AMLBot’s report found that on-chain freezing enforcement of Tether’s USDT stablecoin has been sluggish. As a result, the anti-money laundering firm said, at least $78 million has been lost to bad actors on Ethereum and Tron since 2017. The “laundering loophole” is the result of Tether’s multi-signature contract set up, AMLBot explained in the report. First, a freeze request is sent on-chain which requires multiple signatures to approve before the freeze can be executed. As a result, a “window of opportunity” is created allowing illicit actors to move funds before their address is frozen. One example provided in the report showcases a 44 minute delay between the freeze request and confirmation on Tron. AMLBot claims that $49.6 million has been withdrawn by bad actors on the Tron network since 2017 as a result of the vulnerability. Wallets were able to make up to three transactions during the delay window with 4.88% of blacklisted wallets exploiting the lag on the network. Meanwhile on Ethereum, the firm found $28.5 million USDT withdrawn within the same timeframe. Totalling $78.1 million across the two chains. “Yes, this structure introduces a short delay, but it’s a trade-off for responsible responsiveness to a $100+ billion ecosystem. We are actively refining this process to work to eliminate any potential advantage for bad actors,” a Tether spokesperson told Decrypt . “$76 million referenced in this report should be put in context of the more than $2.7 billion in USD₮ that Tether has successfully frozen and blocked to date,” they added. Tether also said that it finds the phrasing of “loophole” to be “misleading” due to the company’s constant collaboration with law enforcement. The company also pointed to Tether acting faster to freeze assets than stablecoin competitor Circle following the Bybit hack earlier this year. Security firm PeckShield reviewed the report and confirmed that the loophole exists. “It does not necessarily indicate a problem with the contract itself. Rather, it is an operational issue that creates a time window between when the blacklist transaction is submitted and when it is executed,” a PeckShield spokesperson told Decrypt . “Given the security-sensitive nature of the issue, improvements are definitely necessary.” Tether is the issuer of the largest stablecoin in crypto USDT, which aims to peg its price to the U.S. dollar. The company blacklists addresses from trading their products if they’re connected to illegal activity, such as wallets linked to the $1.4 billion Bybit hack earlier this year. Being blacklisted means the address can no longer move Tether issued assets, effectively making the tokens worthless. However, AMLBot believes malicious actors know of the aforementioned lag and are creating tools to exploit it. “Tools can be programmed to monitor the blockchain for specific contract interactions, such as submitTransaction() calls linked to freeze requests,” Slava Demchuk, CEO of AMLBot, told Decrypt . “The bots can alert wallet owners the moment a freeze is initiated but before it’s enforced. Given the delay introduced by Tether’s multi-signature process, this provides a narrow but critical window for illicit actors to quickly move funds.” “While we haven’t directly observed the bots themselves, the on-chain behavior strongly suggests such automation is in play,” he added. PeckShield warned that the lag is inherent to how multi-sig accounts are designed to function. Simply, it takes time to have multiple people sign a transaction despite it being required in some cases to boost security. The firm suggested that Tether could bundle together the freeze request with the signatures into one transaction to eliminate the window. “If you think you can use Tether to move illicit funds, think again. USD₮ is arguably the most traceable asset on the planet, and we will continue working relentlessly with our industry partners to identify you, freeze your funds, and ensure you are brought to justice,” the Tether spokesperson said. Editor’s note: This story was updated to include comments from Tether. Edited by Stacy Elliott. Daily Debrief Newsletter Start every day with the top news stories right now, plus original features, a podcast, videos and more. Source: https://decrypt.co/320223/78m-lost-laundering-loophole-tether-usdt-freezing
You may also like

Ten Thousand Words Interpretation of STRC: Strategy for Making Money to Buy Coins New Magic
The real momentum of the BTC rebound - for every 1 dollar of STRC issued, there corresponds 3 dollars of BTC buying.

What competitive advantages are still defensible in the AI era?
Based on the signals received, determine the direction, and act immediately

For Whom the Bell Tolls, For Whom the Lobster Feeds? A Dark Forest Survival Guide for the 2026 Agent Player
If an AI has read Machiavelli and is much smarter than us, they would be very good at manipulating us — and you wouldn't even realize what's happening.

Circle CEO's Latest Interview: Stablecoins Are Not Cryptocurrency
The true meaning of a stablecoin is to turn the US dollar into an internet-native currency and eventually create an internet financial platform

Deconstructing the Public Chain Pharos Capital Game: Is a $950 million valuation supported by assets like photovoltaics just a shell transaction under layers of betting?
When a physical industry company injects physical assets into a Layer 1 project, it can easily create a valuation of 950 million dollars by calculating several times the value of the physical assets. Is this kind of capital game too outrageous? Does the crypto market really need such RWAs?

a16z: AI is making everyone 10x more productive, but the true winner has yet to emerge
Institutional AI and Retail AI "Better Integration" is an Inevitable Trend.

Why did the star Web3 project Across Protocol choose to abandon DAO?
The proposal for Across to privatize itself is a rare move, but it comes at a time when the industry is beginning to recognize that DAOs are a difficult organizational structure to operate.

In fact, ETH scaling is a major benefit for L2
ETH has finally admitted defeat—its Rollup-centric roadmap is unworkable, while the monolithic scaling solutions adopted by blockchains like Solana have proven to be correct.

Memories: 10 Key Contributions of the TON Core Team That Few People Knew in the Early Days
Every line of code, every tool we build, every sleepless night spent maintaining the network—these efforts have laid the foundation for TON's development today.

2025 South Korea CEX Listing Post-Mortem: Investing in New Coins = 70% Loss?
The 2025 South Korean exchange's new token listing performance is structurally similar to Binance's, with no significant differences.

BIP-360 Analysis: Bitcoin's First Step Towards Quantum Immunity, But Why Only the "First Step"?
This article explains how BIP-360 reshapes Bitcoin's quantum defense strategy, analyzes its enhancements, and discusses why it has not yet achieved full post-quantum security.

50 million USDT exchanged for 35,000 USD AAVE: How did the disaster happen? Who should we blame?
Due to a fatal flaw in the transaction path, a $50 million DeFi operation was executed with almost zero protection, resulting in nearly the entire amount of funds evaporating in a tiny liquidity pool.

The Cryptographic Past of the Middle East
Reality is often more exciting than fiction.

Resolving the Intergenerational Prisoner's Dilemma: The Inevitable Path of Nomadic Capital Bitcoin
When the baby boomer generation collectively sells off, who will become the "greater fool" in the next round of asset crashes?

Who Will Control AI? Why Decentralized AI May Be the Only Alternative to Government and Big Tech
AI has become critical infrastructure, and governments and corporations are competing to control it. Centralized development and regulation are entrenching existing power structures. The Web3 community is building a decentralized alternative — distributed compute, token incentives, and community governance — before that window closes.

Vitalik wrote a proposal teaching you how to secretly use AI large models
Vitalik believes that in the AI era, users should not have to give up their identity to use an AI tool.

On the eve of the explosion of on-chain options
Options are becoming a new anchor in the cryptocurrency market.

WEEX AI Hackathon: How Did This AI Trading Winner Succeed?
A self-taught AI trading enthusiast achieved top-10 results at the WEEX AI Hackathon. Learn about the mindset, AI tools, and lessons behind this impressive performance.
Ten Thousand Words Interpretation of STRC: Strategy for Making Money to Buy Coins New Magic
The real momentum of the BTC rebound - for every 1 dollar of STRC issued, there corresponds 3 dollars of BTC buying.
What competitive advantages are still defensible in the AI era?
Based on the signals received, determine the direction, and act immediately
For Whom the Bell Tolls, For Whom the Lobster Feeds? A Dark Forest Survival Guide for the 2026 Agent Player
If an AI has read Machiavelli and is much smarter than us, they would be very good at manipulating us — and you wouldn't even realize what's happening.
Circle CEO's Latest Interview: Stablecoins Are Not Cryptocurrency
The true meaning of a stablecoin is to turn the US dollar into an internet-native currency and eventually create an internet financial platform
Deconstructing the Public Chain Pharos Capital Game: Is a $950 million valuation supported by assets like photovoltaics just a shell transaction under layers of betting?
When a physical industry company injects physical assets into a Layer 1 project, it can easily create a valuation of 950 million dollars by calculating several times the value of the physical assets. Is this kind of capital game too outrageous? Does the crypto market really need such RWAs?
a16z: AI is making everyone 10x more productive, but the true winner has yet to emerge
Institutional AI and Retail AI "Better Integration" is an Inevitable Trend.