StablR's euro-pegged stablecoin EURR and dollar-pegged USDR crashed below their pegs over the weekend after attackers exploited a 1-of-3 multisig wallet controlling the minting contract. The breach allowed unauthorized minting of roughly $13.5 million worth of tokens, which were then dumped on decentralized exchanges.
Attacker took over owners, minted 8.35M USDR and 4.5M EURR
Security firm Blockaid reported that the exploit originated from the minting contract's governance setup requiring just one of three signatures for administrative control. After compromising a single signer, the attacker replaced the existing owners and minted 8.35 million USDR and 4.5 million EURR in the early hours of the incident.
Onchain investigator ZachXBT tracked the attacker moving funds via Circle's Cross-Chain Transfer Protocol, noting that about $10.4 million worth of the unbacked tokens were swapped into ETH on DEXes. However, slippage cut the eventual realized gain to roughly $2.8 million.
EURR fell to $0.85, USDR hit $0.40 as liquidity dried up
The flood of freshly minted tokens quickly collapsed liquidity. According to CoinGecko, EURR traded near $0.85 after the attack window, while USDR plunged as low as $0.40. USDR later recovered slightly but remained far from parity.
Notably, the attacker also used admin privileges to blacklist and burn tokens. Onchain records show about 2.7 million EURR were removed from a wallet that had been used in normal redemption flows.
Blockaid: governance failure, not a smart contract bug
Blockaid attributed the breach to governance and key-management failure, saying the 1-of-3 signature threshold represented a systemic vulnerability rather than a code-level flaw. The firm warned that weak key management remains a major risk in stablecoin systems.
StablR confirmed the incident hours after onchain activity slowed and said it was assessing the damage. The issuer, licensed by Malta's financial regulator, previously received backing from Tether and Kraken. In early 2025, EURR and USDR had processed over €3 billion in transaction volume and were listed on 50+ exchanges with more than 150 trading pairs.
The attack adds to a growing list of 2026 exploits linked to privileged access and governance breakdowns across crypto protocols.

