StablR Hack
What happened
On May 24, 2026, the StablR stablecoin protocol suffered a critical governance compromise resulting in the unauthorized minting of approximately $12.85M in unbacked $USDR and $EURR.
The exploit was not the result of a smart contract vulnerability, but rather a fundamental failure in key management and governance configuration. The StablR minting authority was governed by a 1-of-3 multisig, which meant that a single compromised private key was sufficient to seize total control over the minting function.
The attacker successfully compromised one of the three keys, then used that access to add their own wallet as a new owner and remove the two legitimate owners. With full control, they minted 8.35 million $USDR and 4.5 million $EURR out of thin air. These unbacked tokens were then immediately dumped into decentralized exchange liquidity pools. Because the pools had limited depth, the attacker was able to extract 1,115 ETH ($2.8M) before the tokens depegged significantly. StablR, a MiCA-compliant project backed by Tether, has yet to announce a formal compensation or freeze plan as they work to contain the impact of the stolen liquidity.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.