Malta-based stablecoin issuer StablR froze its dollar-pegged USDR and euro-pegged EURR tokens on Sunday after an attacker drained a private key from a 1-of-3 multisignature minting wallet, added themselves as administrator, and printed roughly $13.5 million in unbacked stablecoins. The attacker swapped about $10.4 million in face value for 1,115 ETH across decentralized exchanges, netting around $2.8 million in profit and sending EURR to as low as $0.85 and USDR briefly to $0.40 on May 24, 2026. StablR acknowledged the supply is “currently not fully backed at the 1:1 ratio” required under the European Union’s Markets in Crypto-Assets framework, and said it will file an incident report with the Malta Financial Services Authority.
A stablecoin is a cryptocurrency designed to hold a fixed value against a reference asset, usually the U.S. dollar or euro, with reserves held by the issuer to back every token in circulation.
Key takeaways
- $13.5M minted, $2.8M stolen. The attacker minted 8.35 million USDR and 4.5 million EURR, then dumped them on DEXs for 1,115 ETH.
- Single-key failure. StablR’s minting contract used a 1-of-3 multisig threshold, meaning one compromised signer could approve any transaction alone.
- MiCA exposure. StablR holds an Electronic Money Institution license from Malta and must now report under MiCA and the EU’s Digital Operational Resilience Act.
- Pegs broke hard. EURR fell to $0.85 and USDR fell as low as $0.40 before partial recovery; StablR asked exchanges to halt trading and withdrawals.
Published: May 26, 2026 17:00 UTC
What happened
StablR’s USDR and EURR stablecoins depegged on May 24 after an attacker took administrative control of the issuer’s Ethereum-based minting contract. Security firm Blockaid and on-chain analytics provider GoPlus Security both traced the root cause to a compromised private key rather than a smart contract bug, framing the incident as an access-control and operational failure.
The minting wallet was configured with a 1-of-3 multisignature threshold. Any one of three authorized owners could push a transaction through without a co-signer. Once the attacker compromised one key, they added themselves as an administrator, removed the legitimate signers, and minted 8.35 million USDR and 4.5 million EURR at peg, a face value of about $13.5 million.
The attacker then sold the freshly minted tokens for ETH across decentralized exchanges, swapping roughly $10.4 million in face value for 1,115 ETH and clearing about $2.8 million after slippage, according to The Block and on-chain tracking from CoinDesk. EURR fell to $0.85 and USDR fell as low as $0.40 before recovering partially as StablR communicated the freeze.
Why a 1-of-3 multisig was the weak link
The 1-of-3 setup defeats the point of a multisignature wallet. In a properly configured multisig, several signers must independently approve a transaction, so compromising one key buys an attacker nothing. With a 1-of-3 threshold, the wallet provides redundancy for the legitimate operators but no real defense against key theft.
Historical precedent makes the gap clear. Harmony’s Horizon bridge used a 2-of-5 multisig before being drained for $100 million in 2022, and security analysts already flagged that configuration as insufficient at the time. A 1-of-3 threshold on a contract that can mint regulated euro and dollar stablecoins represents a thinner margin of safety than the bridge that became a case study for what not to do.
Regulatory fallout under MiCA
StablR is one of a small group of issuers positioned as a flagship for compliant European stablecoin issuance under the EU’s Markets in Crypto-Assets regulation. It holds an Electronic Money Institution license from the Malta Financial Services Authority and uses Tether’s Hadron platform for tokenization. Tether took a strategic equity stake in StablR in December 2024 ahead of MiCA enforcement.
MiCA requires euro and dollar stablecoin issuers to maintain a 1:1 reserve backing for tokens in circulation. StablR acknowledged in its public statement that the post-exploit supply is no longer fully backed and said it will notify the Malta regulator under MiCA and the EU’s Digital Operational Resilience Act, which mandates incident reporting for licensed financial entities. The episode is the first significant test of MiCA’s enforcement posture against a regulated euro stablecoin issuer.
What comes next
StablR has frozen on-chain operations and asked exchanges to halt trading, deposits, and withdrawals for USDR and EURR. The company has not published a full technical postmortem or a recovery timeline. Expect three near-term flashpoints. First, whether the Malta FSA opens a formal proceeding or imposes capital and operational remedies under MiCA. Second, whether StablR can absorb the $2.8 million loss against its reserves or asks Tether for emergency support. Third, whether other MiCA-licensed issuers preemptively audit their minting infrastructure to avoid a copycat exploit.
For traders, the practical risk is straightforward: any stablecoin that relies on a thin multisig threshold to control issuance is one private-key compromise away from a depeg. The StablR incident makes that risk concrete for regulated European stablecoins, not just experimental DeFi tokens.
FAQ
What is StablR and what are USDR and EURR?
StablR is a Malta-based, MiCA-regulated stablecoin issuer holding an Electronic Money Institution license from the Malta Financial Services Authority. USDR is its dollar-pegged stablecoin and EURR is its euro-pegged stablecoin. The company uses Tether’s Hadron tokenization platform and received a strategic equity investment from Tether in December 2024.
How did the attacker mint $13.5 million in unbacked tokens?
The attacker compromised one private key on StablR’s 1-of-3 minting multisig, then added themselves as an administrator and removed the legitimate signers. They minted 8.35 million USDR and 4.5 million EURR, then sold the tokens on decentralized exchanges for 1,115 ETH, clearing about $2.8 million in profit after slippage.
What does this mean for MiCA stablecoin regulation?
StablR acknowledged that the post-exploit supply is no longer fully backed at the 1:1 ratio required under MiCA. The company will file an incident report with the Malta FSA under MiCA and the EU’s Digital Operational Resilience Act. This is the first significant operational breach at a MiCA-licensed euro stablecoin issuer and a test of how strictly the regulator enforces reserve and resilience requirements.








