StablR's EURR and USDR stablecoins depegged over 20% following a $2.8M exploit.
Security & Exploits ·
Blockaid's exploit detection system identified an ongoing attack on StablR's euro and dollar stablecoins, with approximately $2.8 million extracted so far. Both tokens have depegged over 20% on Ethereum. The attacker exploited a private key compromise affecting the StablREuro minting multisig, which operated on a 1-of-3 threshold—meaning a single compromised key granted full control. The threat actor added themselves as an owner, removed the two legitimate owners, and minted 8.35 million USDR and 4.5 million EURR before swapping roughly $10.4 million in face value across decentralized exchanges, ultimately realizing 1,115 ETH valued at $2.8 million due to constrained liquidity.
This incident stems from key management and governance failure rather than a smart contract vulnerability. StablR, a Maltese electronic money institution issuing both tokens under MiCA compliance, had previously relied on Tether's Hadron tokenization platform for EURR issuance. The breach exposed the risks of multisig configurations with low thresholds and centralized key custody practices.
As of reporting, the StablR team has not issued a public statement regarding the incident or recovery measures. The path to restoring the peg and the mechanisms for user compensation or token redemption remain unannounced.