StablR's EURR and USDR stablecoins depegged after attacker exploited multisig to mint $13.5M in unbacked tokens and dump them on DEXs.
Security & Exploits ·
An attacker exploited a multisig vulnerability in StablR to mint $13.5 million in unbacked EURR and USDR tokens, then dumped roughly $10.4 million in face value across decentralized exchanges. The exploit triggered significant depeg events for both stablecoins: EURR fell to $0.85 and USDR collapsed to as low as $0.40 against their intended $1.00 peg.
The vulnerability lay in the multisig mechanism that governs token minting authority, allowing an unauthorized party to bypass standard safeguards and issue tokens without corresponding collateral or reserves. The attacker then immediately liquidated these unbacked tokens on DEXs, flooding the market and eroding confidence in both assets simultaneously.
Key unknowns remain: the identity of the attacker, the precise technical details of the multisig flaw, whether any funds were recovered, and what remediation StablR has implemented to prevent recurrence. The scale of user losses and the current trading prices of both tokens are not detailed in available reports.