Skip to main content
Sign in

StablR — Multisig Exploit and EURR/USDR Depeg

avoid.net/stablr-multisig-exploit-and-eurr-usdr-depeg28/100·82% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·X1UTad…vwkV

Summary

StablR is a Malta-licensed, MiCA-compliant stablecoin issuer backed by Tether that issues EURR (euro-pegged) and USDR (dollar-pegged) tokens on Ethereum and Solana. On May 24, 2026, an attacker compromised one signer in the platform's 1-of-3 minting multisig, replaced the remaining legitimate owners with malicious addresses, and minted approximately $13.5 million in unbacked tokens, realizing roughly $2.8 million (1,115 ETH) in net proceeds by dumping on decentralized exchanges. Both stablecoins lost significant peg value within hours; as of late July 2026, minting and redemption remain suspended and the reserve deficit had not been publicly resolved.

Connected Entities

1 entities
Organizations
StablR — Multisig Exploit and EURR/USDR Depeg
Relationships
  • + 1 more
Have evidence about StablR — Multisig Exploit and EURR/USDR Depeg?

Timeline(12 events)

July 2024

StablR receives Electronic Money Institution (EMI) license from the Malta Financial Services Authority (MFSA), qualifying it to issue MiCA-compliant stablecoins under EU law.

CoinDesk

17 December 2024

Tether announces a strategic investment in StablR, also agreeing to support compliance infrastructure via its Hadron tokenization platform.

CoinDesk

July 2025

EFRI submits formal concerns to the MFSA alleging governance issues at StablR related to individuals with prior associations with Payvision. No substantive public MFSA response is issued.

EFRI

24 May 2026

Attacker compromises one private key from StablR's 1-of-3 Ethereum minting multisig, replaces all legitimate signers with malicious addresses, and mints approximately 8.35 million USDR and 4.5 million EURR in unbacked tokens (~$13.5M face value). Proceeds of approximately $2.8M (1,115 ETH) are realized via DEX swaps. StablR immediately suspends minting and redemption.

CoinDesk, The Block, StablR official disclosure

24 May 2026

Blockaid issues a community alert identifying the ongoing exploit. GoPlus Security independently confirms the attack as a key-management failure, not a smart contract vulnerability.

Blockaid on X

25 May 2026

StablR publishes its initial public cybersecurity incident disclosure, confirms MiCA reserve backing shortfall, notifies MFSA under DORA, and requests all exchanges suspend trading and withdrawals of EURR and USDR.

StablR official

29 May 2026

StablR formally activates its Recovery Plan under EBA Guidelines and provides notification to the MFSA.

StablR official

5 June 2026

StablR issues further update confirming ongoing suspension of minting and redemption and continued forensic investigation.

StablR official

15 June 2026

StablR three-week status report confirms incident is contained with no further unauthorized minting since May 24; minting and redemption remain suspended as a precautionary measure.

StablR official

24 June 2026

StablR issues notification update maintaining suspension status with no material changes.

StablR official

8 July 2026

StablR issues its most recent public update (as of July 22, 2026), reporting 'no material changes' to its prior disclosures; minting and redemption remain suspended.

EFRI citing StablR official

22 July 2026

EFRI publishes analysis identifying gaps in public MFSA oversight and critical undisclosed information from StablR, including root cause, number of unauthorized tokens, reserve deficit size, and redemption timeline.

EFRI
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 18 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/12/2026, 12:05:54 PM

last updated: 8/25/2026, 6:03:43 PM

5 views

avoid.net — verified advice for a post-truth world