Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

StablR Euro Exploit Mints 8.35M USDR & 4.5M EURR as EURR and USDR Lose Their Pegs

Attacker Gains Control of 1-of-3 Multisig, Mints $13M Face Value Unbacked Tokens and Drains ~$2.8M in ETH

Akil Prasath LV by Akil Prasath LV
May 25, 2026
in Security & Hacks
0 0
Share on FacebookShare on Twitter

StablR’s EURR and USDR stablecoins lost their pegs today after an attacker exploited a 1-of-3 multisig wallet tied to the project’s minting contract. The intruder minted roughly 8.35 million unbacked USDR and 4.5 million EURR – tokens with a combined face value near $13.5 million – then dumped them across decentralized exchanges for approximately 1,115 ETH, realizing around $2.8 million in profit amid heavy slippage.

The depeg hit fast. EURR, designed to track the euro at 1:1, traded as low as €0.85–0.90 in the hours following the mint. USDR, pegged to the dollar, fell even harder, dipping below $0.70 at points and hovering in the $0.40–$0.80 range depending on the pool and timing. Liquidity thinned out quickly as traders rushed to exit, amplifying the price action on Ethereum where the affected contracts sit. The price of EURR, USDR plummeted following the exploit.

StablR USDR, StablR EURR Stablecoin Depegs After Governance Exploit
StablR Euro Depegged Price Chart

The Attack Vector: Not a Smart Contract Bug, But a Governance Failure

On-chain investigator ZachXBT was the first to flag the unusual minting activity.

The root cause was straightforward and painful: an attacker gained control of one private key belonging to a multisig signer. With just 1-of-3 approval required for the minting admin role, that single key was enough to remove the legitimate owners, add their own wallet, and authorize unlimited issuance with zero collateral behind it.

This wasn’t a vulnerability in the token contracts themselves. Audits had previously confirmed the 1:1 fiat reserves held by StablR. The problem sat entirely in the operational layer – key custody and multisig configuration for the most sensitive function any stablecoin issuer controls: the ability to create new supply.

StablR operates as a Malta-licensed Electronic Money Institution (EMI) and positions itself as fully MiCA-compliant. The project has attracted backing and investment from Tether, and it emphasizes proof-of-reserve attestations while bridging traditional finance rails to DeFi on Ethereum (and reportedly Solana). Yet the minting authority relied on what many now see as an outdated and dangerously thin security setup.

The Attacker’s Wallet and Timeline

The attacker operated from Ethereum address 0xea480c23d7b29a515856aafe0dc86f7519965a04. On-chain activity suggests the exploit unfolded overnight in European time zones, when monitoring may have been lighter. By the time the first alerts surfaced, the attacker had already swapped the freshly printed tokens and withdrawn the ETH proceeds. Some six-figure amounts were later frozen by security teams, but the bulk of the realized gain had already left the ecosystem.

StablR Team’s Official Response

Security update: We have identified an exploit affecting StablR and are actively working to contain it and minimize impact.

Protecting our users and your funds is our top priority.

We’ll share verified details and next steps as soon as possible.

— StablR (@StablREuro) May 24, 2026

That post arrived roughly eight hours after the last suspicious transactions. No immediate freeze of the entire supply or detailed recovery roadmap was included in the initial update. Trading in both EURR and USDR remains volatile as this article publishes, with thin order books reflecting the sudden loss of confidence.

What Makes This Different — And Why Reserves Still Matter

Unlike algorithmic failures such as Terra’s UST collapse, StablR’s underlying fiat reserves appear untouched. Previous attestations showed full backing, and nothing in today’s incident suggests the attacker drained the actual cash or treasury accounts. The depeg stems purely from an artificial oversupply hitting the secondary market – a classic symptom of minting authority being hijacked rather than a solvency crisis.

That distinction matters for holders. In theory, once StablR regains control of the minting contract, burns or redeems the excess supply, and restores proper governance, the peg has a clear path back to parity. But the window between exploit and full resolution is exactly where trust evaporates. Traders are pricing in the operational risk right now, not the fundamental backing.

Broader Lessons for MiCA-Era Stablecoins

This event lands at a sensitive moment for European stablecoin regulation. MiCA was meant to bring credibility and consumer protection to issuers like StablR through licensing, reserve requirements, and transparency mandates. Yet it does not – and realistically cannot – micromanage every multisig threshold or key-storage practice.

The gap is now obvious: compliance covers the vault, but the printing press still depends on human-controlled admin keys. A 1-of-3 setup for a project handling tens of millions in stablecoin supply was always going to be a single point of failure once one key was compromised, whether through phishing, insider access, or targeted social engineering.

StablR is not the first project to learn this the hard way, but it may be the highest-profile regulated European issuer to face it publicly. The incident will likely accelerate conversations around mandatory time-locks, hardware security modules, distributed key management, and real-time monitoring requirements for minting authorities under future MiCA guidance or national implementations.

For the wider market, the message is blunt. Even “institutional-grade,” Tether-backed, MiCA-licensed stablecoins carry governance risk that cannot be fully outsourced to regulators. Proof-of-reserve is necessary but not sufficient when the issuance mechanism itself can be hijacked in minutes.

StablR has built a solid reputation over the past year as a compliant bridge between TradFi and on-chain liquidity. Today’s exploit tests whether that reputation can survive a real-world stress event. The next 24–48 hours will be critical: clear communication on exactly how much excess supply exists, how it will be clawed back or burned, and what upgraded multisig or custody measures will prevent recurrence.

Until then, the depeg serves as a live reminder that stable doesn’t always mean bulletproof – especially when the weakest link is still a private key.

Stay tuned for updates as StablR provides verified on-chain details and a full post-mortem. This coverage draws directly from blockchain data, ZachXBT’s investigation, and the issuer’s own statements.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacksstablecoin

Related Posts

Suspected Exploit Drains Polymarket UMA CTF Adapter of Over $660,000 in POL Tokens on Polygon
Security & Hacks

Suspected Exploit Drains Polymarket UMA CTF Adapter of Over $660,000 in POL Tokens on Polygon

by Akil Prasath LV
May 22, 2026

The leading prediction market platform Polymarket is dealing with a suspected exploit on its UMA CTF Adapter contract deployed on...

Read moreDetails
MAP Protocol

MAP Protocol’s MAPO Token Crashes Nearly 96% After Major Butter Bridge Exploit

May 21, 2026
Kraken and Coinbase User Loses $6.7M After Apparent Physical Attack

Kraken and Coinbase User Loses $6.7M Following Suspected Targeted Attack

May 20, 2026 - Updated on May 21, 2026
Sorted Wallet Raises $4.4 Million to Expand Stablecoin Payments Across Emerging Markets

Sorted Wallet Raises $4.4 Million to Expand Stablecoin Payments Across Emerging Markets

May 20, 2026
Bankr AI Crypto Wallet Hack

Bankr AI Crypto Wallet Hack: 14 Base Network Wallets Breached in Security Incident

May 20, 2026
Checker Raises $8 Million as Investors Increase Focus on Stablecoin Infrastructure

Checker Raises $8 Million as Investors Increase Focus on Stablecoin Infrastructure

May 20, 2026
Japan LDP Unveils AI and Blockchain Financial Vision

Japan LDP Unveils AI and Blockchain Financial Vision

May 19, 2026

Recommended

  • All
  • News

StablR Euro Exploit Mints 8.35M USDR & 4.5M EURR as EURR and USDR Lose Their Pegs

May 25, 2026
Cardano Faces Major Internal Rift

Cardano Faces Major Internal Rift Over $52M Research Funding Proposal

May 23, 2026
Bitcoin Falls Below $75K as $400 Million in Long Liquidations Shake Crypto Market

Bitcoin Falls Below $75K as $400 Million in Long Liquidations Shake Crypto Market

May 23, 2026
Pudgy Penguins’ PENGU Token Slides 14% as Crypto Market Weakness Hits High-Risk Altcoins

Pudgy Penguins’ PENGU Token Slides 14% as Crypto Market Weakness Hits High-Risk Altcoins

May 23, 2026

StablR Euro Exploit Mints 8.35M USDR & 4.5M EURR as EURR and USDR Lose Their Pegs

May 25, 2026
Cardano Faces Major Internal Rift

Cardano Faces Major Internal Rift Over $52M Research Funding Proposal

May 23, 2026
Bitcoin Falls Below $75K as $400 Million in Long Liquidations Shake Crypto Market

Bitcoin Falls Below $75K as $400 Million in Long Liquidations Shake Crypto Market

May 23, 2026
Pudgy Penguins’ PENGU Token Slides 14% as Crypto Market Weakness Hits High-Risk Altcoins

Pudgy Penguins’ PENGU Token Slides 14% as Crypto Market Weakness Hits High-Risk Altcoins

May 23, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • StablR Euro Exploit Mints 8.35M USDR & 4.5M EURR as EURR and USDR Lose Their Pegs
  • Cardano Faces Major Internal Rift Over $52M Research Funding Proposal
  • Bitcoin Falls Below $75K as $400 Million in Long Liquidations Shake Crypto Market

Categories

  • AI × Crypto
  • Data & Dashboards
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.