Incident case file
Sign in to watchStablR (EURR + USDR) — 1-of-3 Minting Multisig Key Compromise
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xea480c23d7b29a515856aafe0dc86f7519965a04 (primary attacker wallet, per ZachXBT; funded via CCTP on Noble). Mint-executing wallet: 0xD4677B5A8B1b97EA213Fdb876b0FcBAB3f9F6CD1.
Timeline: Late on 23 May into 24 May 2026, an attacker who compromised a single signer key on StablR's 1-of-3 minting multisig added themselves as an owner, removed the two legitimate signers, and minted roughly $13.5M of unbacked stablecoins (about 8,350,000 USDR and 4,500,000 EURR). The tokens were dumped on Uniswap V3, where thin liquidity meant the attacker realised only about $2.8M (~1,115 ETH) of the $13.5M nominal mint. ZachXBT flagged the attack publicly at ~01:46 UTC on 24 May, publishing the attacker wallet and a CCTP-on-Noble funding link, and coordinated a partial freeze. StablR issued a statement around 12:10 UTC on 24 May and, by 26 May, suspended minting and redemption, notified Malta's MFSA under MiCA/DORA, and engaged external cybersecurity firms and law enforcement. EURR depegged severely (to roughly $0.55-0.86 intraday) while USDR recovered toward $0.994 by 26-27 May. Blockaid and GoPlus attributed the incident to a key-management and governance failure rather than a smart-contract bug. StablR holds an Electronic Money Institution license from the MFSA (July 2024) and had taken strategic investment from Tether (Dec 2024) and Kraken (July 2025). No user compensation had been announced as of the cutoff, and recovery beyond the partial freeze was 0%.
Sources and coverage
- Articletheblock.cohttps://www.theblock.co/post/402429/stablrs-eurr-and-usdr-depeg-after-attacker-mints-13-5-million-in-unbacked-tokens-through-multisig-exploit
- Articleccn.comhttps://www.ccn.com/education/crypto/stablr-hack-eurr-usdr-collapse-mica-compliance/
- Articlecryip.cohttps://cryip.co/stablr-stablecoin-exploit-full-technical-analysis-13-5m-multisig-attack/
- Articleen.cryptonomist.chhttps://en.cryptonomist.ch/2026/05/26/stablr-usdr-eurr-hack-mica/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/25/can-mica-prevent-multisig-hacks-stablrs-10m-exploit-exposes-the-gap/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)