StablR Stablecoins EURR and USDR Depeg After $13.5M Exploit

StablR Stablecoins EURR and USDR Depeg After $13.5M Exploit

N
News Editor 01
2026-07-23 09:15:16
StablR's EURR and USDR stablecoins lost their peg after a $13.5 million unauthorized minting exploit via a compromised 1-of-3 multisig wallet. EURR dropped to ~$0.85, USDR to ~$0.40. Blockaid attributed the breach to governance failure.
stablecoinhackmultisig vulnerabilityStablRdepeg

StablR's euro-pegged stablecoin EURR and dollar-pegged USDR crashed below their pegs over the weekend after attackers exploited a 1-of-3 multisig wallet controlling the minting contract. The breach allowed unauthorized minting of roughly $13.5 million worth of tokens, which were then dumped on decentralized exchanges.

Attacker took over owners, minted 8.35M USDR and 4.5M EURR

Security firm Blockaid reported that the exploit originated from the minting contract's governance setup requiring just one of three signatures for administrative control. After compromising a single signer, the attacker replaced the existing owners and minted 8.35 million USDR and 4.5 million EURR in the early hours of the incident.

Onchain investigator ZachXBT tracked the attacker moving funds via Circle's Cross-Chain Transfer Protocol, noting that about $10.4 million worth of the unbacked tokens were swapped into ETH on DEXes. However, slippage cut the eventual realized gain to roughly $2.8 million.

EURR fell to $0.85, USDR hit $0.40 as liquidity dried up

The flood of freshly minted tokens quickly collapsed liquidity. According to CoinGecko, EURR traded near $0.85 after the attack window, while USDR plunged as low as $0.40. USDR later recovered slightly but remained far from parity.

Notably, the attacker also used admin privileges to blacklist and burn tokens. Onchain records show about 2.7 million EURR were removed from a wallet that had been used in normal redemption flows.

Blockaid: governance failure, not a smart contract bug

Blockaid attributed the breach to governance and key-management failure, saying the 1-of-3 signature threshold represented a systemic vulnerability rather than a code-level flaw. The firm warned that weak key management remains a major risk in stablecoin systems.

StablR confirmed the incident hours after onchain activity slowed and said it was assessing the damage. The issuer, licensed by Malta's financial regulator, previously received backing from Tether and Kraken. In early 2025, EURR and USDR had processed over €3 billion in transaction volume and were listed on 50+ exchanges with more than 150 trading pairs.

The attack adds to a growing list of 2026 exploits linked to privileged access and governance breakdowns across crypto protocols.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.