StablR Hack

TOTAL LOST $12.8M
High Access Control Attacks

What happened

On May 24, 2026, the StablR stablecoin protocol suffered a critical governance compromise resulting in the unauthorized minting of approximately $12.85M in unbacked $USDR and $EURR.

The exploit was not the result of a smart contract vulnerability, but rather a fundamental failure in key management and governance configuration. The StablR minting authority was governed by a 1-of-3 multisig, which meant that a single compromised private key was sufficient to seize total control over the minting function.

The attacker successfully compromised one of the three keys, then used that access to add their own wallet as a new owner and remove the two legitimate owners. With full control, they minted 8.35 million $USDR and 4.5 million $EURR out of thin air. These unbacked tokens were then immediately dumped into decentralized exchange liquidity pools. Because the pools had limited depth, the attacker was able to extract 1,115 ETH ($2.8M) before the tokens depegged significantly. StablR, a MiCA-compliant project backed by Tether, has yet to announce a formal compensation or freeze plan as they work to contain the impact of the stolen liquidity.

Affected Tokens:

USDR: 0x7b43e387…63c8f8

EURR: 0x50753cfa…91e408

Case & protocol details

Classification Stablecoin
Protocol Type Exploit/Access control
Official Website www.stablr.com/
Protocol Twitter/X @StablREuro

Market Context at Time of Hack

Token Price at Hack $0.9985
Market Cap at Hack $6.7M
% of Market Cap Stolen 100.00%
Token Categories
Enterprise Solutions Payments Staking Governance Layer 1 Binance Alpha Binance Alpha Airdrops Binance Ecosystem

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.