Share this article

Tether Code 'Flaw' Was Actually an Exchange Error

A suspected vulnerability in Tether's code for its USDT stablecoin has been confirmed as an exchange integration issue, not a protocol bug.

Updated Sep 13, 2021, 8:07 a.m. Published Jun 29, 2018, 3:16 p.m.
usdt2

Suggestions that the code for Tether's dollar-pegged cryptocurrency USDT may contain an error that can be exploited to allow double spending appear to be false.

According to the latest statements from both blockchain security firm Slow Mist, the company that made the original claim, and Tether, the startup that provides software for USDT, the issue is actually down to an exchange integration flaw.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

On Thursday, Slow Mist seemed to claim in a WeChat post that when an exchange is conducting a transaction with USDT, the exchange needs to verify that the transactions details are "true," otherwise a double spend can occur. The company further suggested that the problem had been used in an attack on an unnamed crypto exchange, and, in a post on Twitter, included a page of transaction data with some of the details blurred out.

The claims, if true, were potentially impactful, as the USDT token is notably used to substitute for the U.S. dollar, acting as a proxy to quickly shift funds around exchanges rather than wait for wire transfers from banks.

However, in a statement, a spokesperson for Tether emphasized that the issue was not part of the USDT protocol.

They told CoinDesk:

"Rather, it was due to a faulty integration of Tether at the exchange level. While we can't exercise much control over how exchanges execute the integration process, we've provided integration guides in this instance to help solve the issue and will continue to assist any other exchanges in their USDT integration processes."

Now, Slow Mist has also clarified that the issue does, in fact, lie with how exchanges integrate the USDT protocol for transactions, and not with the protocol itself.

In a statement to CoinDesk, the company said, "There was no Tether vulnerability [itself], but rather poor handling of incoming transactions. We have updated Twitter to explain this issue. We are sorry to say that the previous description did not express clearly."

While apparently not a Tether issue, the developments may add to the industry nervousness around the firm, which has been the subject of controversy alongside Bitfinex, the cryptocurrency exchange to which it is closely linked. Critics have alleged that Tether's USDT token is, in spite of its claims, not fully backed by a supply of U.S. dollars and has instead been used to manipulate the cryptocurrency market.

Just last week, Tether released a report attesting to its U.S. dollar reserves as proof that the token is fully backed. As CoinDesk highlighted, though, the report falls short of serving as a fall audit of Tether's finances and comes months after the company's relationship with auditing firm Friedman came to an end.

After Slow Mist's original post caused widespread concerns over security, several exchanges including OKEx and ZB.com verified that they were unaffected by the issue.

LBank announced it "conducted an emergency technical investigation," finding that it was not vulnerable. However, the exchange stated that "we cannot guarantee the security of the other trading platforms and USDT as a whole, so we decided to close the USDT recharge temporarily."

Editor's note: Some statements in this article have been translated from Chinese.

Tether image via Shutterstock

More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

BNB rises 2.5%, nears $900 mark as prediction market growth signals utility expansion

BNB price chart showing a slight 1% increase to $882 amid growing institutional interest and technical consolidation.

A new physically backed BNB exchange-traded product launched on Nasdaq Stockholm, adding to existing investment options.

What to know:

  • BNB token climbed 2.5% to $89e, approaching the $900 resistance level, with increased trading volume suggesting fresh buying interest.
  • A new physically backed BNB exchange-traded product launched on Nasdaq Stockholm, adding to existing investment options like Grayscale's pending ETF filing.
  • BNB Chain saw significant growth in prediction markets, with platforms like Opinion Labs logging over $700 million in 7-day trading volume and cumulative trading volumes crossing $20 billion.