{"investigation":{"slug":"stablr-multisig-exploit-and-eurr-usdr-depeg-may-2026","entity_name":"StablR Multisig Exploit and EURR/USDR Depeg (May 2026)","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.75,"status":"draft","content_type":"investigation","summary":"On 24 May 2026, an attacker compromised a private key belonging to one of three signers on StablR's minting multisignature wallet — reportedly secured by only a 1-of-3 threshold — and used it to mint roughly $13.5 million in unbacked EURR and USDR tokens, selling approximately $2.8 million worth into decentralized exchanges before the exploit was contained. Both euro-pegged EURR and dollar-pegged USDR lost their pegs, StablR suspended minting and redemption, and as of late August 2026 the tokens remained under-collateralized and redemption remained suspended, prompting renewed regulatory scrutiny of the Malta-licensed issuer. The incident also drew attention to pre-existing allegations, raised by the advocacy group EFRI and FinTelegram, concerning StablR management's past role at Dutch payment processor Payvision.","sections":[{"content":"On 24 May 2026, an attacker gained administrative control over the minting contract for StablR's EURR (euro-pegged) and USDR (dollar-pegged) stablecoins. According to on-chain analysis reported by The Block and CoinDesk, the minting multisignature wallet used a 1-of-3 approval threshold, meaning control of a single compromised private key was sufficient to authorize changes. The attacker allegedly added themselves as an administrator, removed or replaced the legitimate signers, and minted approximately 8.35 million USDR and 4.5 million EURR (a combined face value of roughly $13.5 million) without corresponding collateral backing. The attacker reportedly swapped about $10.4 million in face value of the minted tokens for approximately 1,115 ETH on decentralized exchanges, netting an estimated $2.8 million after slippage; a separate wallet linked to the attacker was reported to hold roughly $3.15 million (1,488 ETH) shortly after the incident. Blockchain investigator ZachXBT was reported to have publicly flagged the exploit on-chain before StablR issued a public acknowledgment. Security firm Blockaid characterized the incident as an access-control and key-management failure rather than a smart-contract vulnerability.","heading":"The May 2026 Multisig Exploit","sources":[{"url":"https://www.theblock.co/news/regulation/2026-05-24-stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit-402429","name":"StablR's EURR and USDR depeg after attacker mints $13.5 million in unbacked tokens through multisig exploit","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/05/26/stablr-freezes-usdr-and-eurr-after-attacker-mints-usd13-5-million-in-unbacked-tokens","name":"StablR freezes USDR and EURR after attacker mints $13.5 million in unbacked tokens","type":"news_article","credibility":2},{"url":"https://stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations","name":"StablR Discloses Cybersecurity Incident Affecting USDR and EURR Token Operations","type":"official","credibility":2}],"severity":"critical"},{"content":"Following the unauthorized minting and DEX sell-off, both StablR tokens broke their pegs. Reports vary somewhat on exact low points depending on the timing and venue sampled: The Block reported EURR falling to about $0.85 (versus its euro-linked target near $1.15) and USDR briefly touching about $0.40 before recovering toward roughly $0.64; CoinDesk reported EURR trading around $0.548 versus a roughly €1.16 baseline, and USDR recovering to about $0.994. StablR's own disclosure confirmed the circulating supply of both tokens was no longer fully backed at the required 1:1 ratio under the EU's Markets in Crypto-Assets Regulation (MiCAR). StablR requested that all listed exchanges and trading venues suspend trading, deposits, and withdrawals of EURR and USDR.","heading":"EURR/USDR Depeg and Market Impact","sources":[{"url":"https://www.theblock.co/news/regulation/2026-05-24-stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit-402429","name":"StablR's EURR and USDR depeg after attacker mints $13.5 million in unbacked tokens through multisig exploit","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/markets/2026/05/26/stablr-freezes-usdr-and-eurr-after-attacker-mints-usd13-5-million-in-unbacked-tokens","name":"StablR freezes USDR and EURR after attacker mints $13.5 million in unbacked tokens","type":"news_article","credibility":2}],"severity":"critical"},{"content":"StablR stated it notified the Malta Financial Services Authority (MFSA) of a Major ICT-Related Incident under the EU's Digital Operational Resilience Act (DORA), submitted required MiCAR notifications, and engaged external cybersecurity specialists and law enforcement. On 29 May 2026, StablR's board activated a formal recovery plan that continued the temporary suspension of minting and redemption; the company stated the underlying safeguarded (fiat) assets backing the stablecoins were unaffected by the breach itself, but did not provide a timetable for lifting the suspension. According to reporting by the advocacy group EFRI, StablR disclosed on 25 August 2026 — more than three months after the incident — that approximately 6.41 million EURR and 14.33 million USDR of unauthorized tokens remained in circulation, and that minting and redemption were still suspended with no announced resumption date. EFRI also alleged that as of 28 August 2026 StablR's website continued to describe the tokens as 'fully collateralized' despite the disclosed shortfall, and questioned whether the MFSA had made a formal determination under MiCAR Article 46(4) regarding the continued suspension. These EFRI claims are sourced to a single advocacy organization and have lower independent corroboration; they are presented here as allegations pending confirmation by regulators or additional outlets.","heading":"Regulatory Notification and Ongoing Suspension","sources":[{"url":"https://stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations","name":"StablR Discloses Cybersecurity Incident Affecting USDR and EURR Token Operations","type":"official","credibility":2},{"url":"https://stablr.com/insights/important-notice-to-stablr-token-holders-recovery-plan-activation","name":"Important Notice to StablR Token Holders: Recovery Plan Activation","type":"official","credibility":2},{"url":"https://efri.io/stablr-discloses-scale-of-unbacked-tokens-one-day-after-efri-renewed-its-mfsa-request/","name":"StablR discloses scale of unbacked tokens one day after EFRI renewed its MFSA request","type":"community_report","credibility":3},{"url":"https://efri.io/stablr-cyber-incident-mfsa-supervision/","name":"StablR Cyber Incident: What Did the MFSA Supervise?","type":"community_report","credibility":3}],"severity":"high"},{"content":"Independent of the May 2026 exploit, StablR's leadership has faced scrutiny over prior roles at Dutch payment processor Payvision B.V. According to compliance-focused publication Vixio, Dutch prosecutors (Openbaar Ministerie) issued penalty orders in April 2024 — fines of €150,000 and €180,000 — against two former Payvision directors for structural anti-money-laundering (AML) and counter-terrorist-financing violations. Advocacy group EFRI and investigative outlet FinTelegram have alleged that StablR founder and CEO Gijs op de Weegh served as Payvision's COO and, per FinTelegram's reporting, signed merchant agreements with entities EFRI has linked to fraud schemes that allegedly funneled approximately €150 million in scam proceeds through Payvision between 2015 and 2019. EFRI has separately urged the MFSA to review StablR's Electronic Money Institution (EMI) license, citing these management history concerns and questions about StablR's ownership structure via Dutch holding company Plutus B.V. and its links to Rudolf Booker, Payvision's former CEO. These allegations originate primarily from an advocacy organization (EFRI) and an investigative outlet (FinTelegram) rather than a court finding that directly names op de Weegh; the Vixio-reported AML fines against unnamed 'former Payvision directors' provide independent, higher-credibility corroboration that structural AML failures occurred at Payvision, but do not by themselves establish personal culpability for any specific named individual. This section should be read as reporting unverified allegations, not an adjudicated finding.","heading":"Pre-Existing Governance Concerns: Management's Payvision History","sources":[{"url":"https://www.vixio.com/insights/pc-former-payvision-execs-fined-aml-failures","name":"Former Payvision Execs Fined For AML Failures","type":"news_article","credibility":2},{"url":"https://fintelegram.com/payvision-scandal-dutch-authorities-cover-up-fraud-former-coo-now-runs-regulated-stablecoin-provider/","name":"Payvision Scandal: Dutch Authorities Cover Up Fraud, Former COO Now Runs Regulated Stablecoin Provider","type":"community_report","credibility":3},{"url":"https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/","name":"EFRI urges MFSA to review StablR's EMI Licence","type":"community_report","credibility":3}],"severity":"medium"},{"content":"For balance: prior to the exploit, StablR had attracted institutional investment and had obtained MiCA-related authorization, factors that some observers may weigh against the risks identified above. Reporting cited by The Block indicates Tether made a strategic investment in StablR around December 2024, and Kraken made a strategic investment around July 2025. StablR held an MFSA-granted Electronic Money Institution license, reported by EFRI to have been granted on 21 June 2024. These facts do not resolve the governance and security concerns described elsewhere in this report but are included for completeness.","heading":"Institutional Backing Context","sources":[{"url":"https://www.theblock.co/news/regulation/2026-05-24-stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit-402429","name":"StablR's EURR and USDR depeg after attacker mints $13.5 million in unbacked tokens through multisig exploit","type":"news_article","credibility":2},{"url":"https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/","name":"EFRI urges MFSA to review StablR's EMI Licence","type":"community_report","credibility":3}],"severity":"low"}],"timeline":[{"date":"2024-04","event":"Dutch prosecutors (Openbaar Ministerie) issued penalty orders (€150,000 and €180,000 fines) against two former Payvision directors for structural AML/CFT violations, according to Vixio.","source":"Vixio","source_url":"https://www.vixio.com/insights/pc-former-payvision-execs-fined-aml-failures"},{"date":"2024-06-21","event":"MFSA granted StablR its Electronic Money Institution (EMI) license.","source":"EFRI","source_url":"https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/","date_evidence":"\"21 June 2024\": MFSA granted StablR's Electronic Money Institution licence"},{"date":"2024-12","event":"Tether reported to have made a strategic investment in StablR.","source":"The Block","source_url":"https://www.theblock.co/news/regulation/2026-05-24-stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit-402429"},{"date":"2025-07","event":"Kraken reported to have made a strategic investment in StablR; EFRI separately urged MFSA to review StablR's EMI license around this period.","source":"The Block / EFRI","source_url":"https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/"},{"date":"2026-05","event":"Attacker compromised a private key on StablR's 1-of-3 minting multisig, minted approximately $13.5 million in unbacked EURR and USDR, and sold roughly $10.4 million of face value on DEXs, netting an estimated $2.8 million. Blockchain investigator ZachXBT publicly flagged the activity; StablR later acknowledged the exploit and suspended minting and redemption.","source":"StablR official disclosure / The Block","source_url":"https://stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations","date_evidence":"Incident Date: Sunday 24th May 2026","date_original":"2026-05-24"},{"date":"2026-05-26","event":"CoinDesk reported StablR had frozen USDR and EURR operations, requested exchanges halt trading, and notified the MFSA under DORA.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/05/26/stablr-freezes-usdr-and-eurr-after-attacker-mints-usd13-5-million-in-unbacked-tokens","date_evidence":"May 26, 2026, 7:25 a.m. EDT"},{"date":"2026-05","event":"StablR's Board of Directors formally activated a recovery plan continuing the suspension of minting and redemption, with no timetable given for resumption.","source":"StablR official notice","source_url":"https://stablr.com/insights/important-notice-to-stablr-token-holders-recovery-plan-activation"},{"date":"2026-08","event":"EFRI submitted a renewed supervisory request concerning StablR to the MFSA, copied to the European Banking Authority; StablR subsequently disclosed that approximately 6.41 million EURR and 14.33 million USDR of unauthorized tokens remained in circulation, with minting and redemption still suspended.","source":"EFRI","source_url":"https://efri.io/stablr-discloses-scale-of-unbacked-tokens-one-day-after-efri-renewed-its-mfsa-request/"}],"sources_used":[{"url":"https://www.theblock.co/news/regulation/2026-05-24-stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit-402429","name":"StablR's EURR and USDR depeg after attacker mints $13.5 million in unbacked tokens through multisig exploit","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/markets/2026/05/26/stablr-freezes-usdr-and-eurr-after-attacker-mints-usd13-5-million-in-unbacked-tokens","name":"StablR freezes USDR and EURR after attacker mints $13.5 million in unbacked tokens","type":"news_article","archive_url":"http://web.archive.org/web/20260921095939/https://www.coindesk.com/markets/2026/05/26/stablr-freezes-usdr-and-eurr-after-attacker-mints-usd13-5-million-in-unbacked-tokens","credibility":2,"archive_timestamp":"2026-09-21T09:59:39+00:00"},{"url":"https://stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations","name":"StablR Discloses Cybersecurity Incident Affecting USDR and EURR Token Operations","type":"official","archive_url":"http://web.archive.org/web/20260812184708/https://www.stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations","credibility":2,"archive_timestamp":"2026-08-12T18:47:08+00:00"},{"url":"https://stablr.com/insights/important-notice-to-stablr-token-holders-recovery-plan-activation","name":"Important Notice to StablR Token Holders: Recovery Plan Activation","type":"official","archive_url":"http://web.archive.org/web/20260812184708/https://www.stablr.com/insights/important-notice-to-stablr-token-holders-recovery-plan-activation","credibility":2,"archive_timestamp":"2026-08-12T18:47:08+00:00"},{"url":"https://efri.io/stablr-discloses-scale-of-unbacked-tokens-one-day-after-efri-renewed-its-mfsa-request/","name":"StablR discloses scale of unbacked tokens one day after EFRI renewed its MFSA request","type":"community_report","archive_url":"http://web.archive.org/web/20260913043446/https://efri.io/stablr-discloses-scale-of-unbacked-tokens-one-day-after-efri-renewed-its-mfsa-request/","credibility":3,"archive_timestamp":"2026-09-13T04:34:46+00:00"},{"url":"https://efri.io/stablr-cyber-incident-mfsa-supervision/","name":"StablR Cyber Incident: What Did the MFSA Supervise?","type":"community_report","archive_url":"http://web.archive.org/web/20260812122029/https://efri.io/stablr-cyber-incident-mfsa-supervision/","credibility":3,"archive_timestamp":"2026-08-12T12:20:29+00:00"},{"url":"https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/","name":"EFRI urges MFSA to review StablR's EMI Licence","type":"community_report","archive_url":"http://web.archive.org/web/20260812122056/https://efri.io/efri-urges-mfsa-to-review-stablrs-emi-license/","credibility":3,"archive_timestamp":"2026-08-12T12:20:56+00:00"},{"url":"https://www.vixio.com/insights/pc-former-payvision-execs-fined-aml-failures","name":"Former Payvision Execs Fined For AML Failures","type":"news_article","archive_url":"http://web.archive.org/web/20260211223247/https://www.vixio.com/insights/pc-former-payvision-execs-fined-aml-failures","credibility":2,"archive_timestamp":"2026-02-11T22:32:47+00:00"},{"url":"https://fintelegram.com/payvision-scandal-dutch-authorities-cover-up-fraud-former-coo-now-runs-regulated-stablecoin-provider/","name":"Payvision Scandal: Dutch Authorities Cover Up Fraud, Former COO Now Runs Regulated Stablecoin Provider","type":"community_report","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crowdfundinsider.com/2026/05/281637-stablr-eurr-and-usdr-stablecoins-break-peg-following-multisig-compromise-and-unauthorized-token-creation/","name":"StablR EURR And USDR Stablecoins Break Peg Following Multisig Compromise And Unauthorized Token Creation","type":"news_article","archive_url":"https://web.archive.org/web/20260924031922/https://www.crowdfundinsider.com/2026/05/281637-stablr-eurr-and-usdr-stablecoins-break-peg-following-multisig-compromise-and-unauthorized-token-creation/","credibility":2,"archive_timestamp":"2026-09-24T03:19:22+00:00"},{"url":"https://www.ccn.com/education/crypto/stablr-hack-eurr-usdr-collapse-mica-compliance/","name":"$2.8M StablR Hack Triggers EURR and USDR Collapse Despite MiCA Compliance","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-23T23:18:20.735803+00:00","updated_at":"2026-09-24T09:50:37.512199+00:00"}}