StablR hack — May 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 25, 2026 |
| Target type | Stablecoin or yield protocol |
| Loss | $2,800,000Published estimates range $2,800,000 to $13,500,000Price at time of incident |
| Method | Private key compromiseA single key belonging to an owner of the minting multisig was compromised. CoinDesk, citing GoPlus, reports the wallet was configured with a 1-of-3 threshold, so any one owner could approve alone. Per Blockaid, the attacker added their own address as an owner, removed the legitimate signers, minted roughly 8.35 million USDR and 4.5 million EURR on Ethereum, and sold the tokens into decentralised exchange liquidity for about 1,115 ETH. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
StablR, a Malta-authorised issuer of the euro stablecoin EURR and the dollar stablecoin USDR, identified unauthorised external access to its platform infrastructure on Sunday 24 May 2026 and disclosed it publicly the following day. In its own statement the company said it had identified irregularities after receiving alerts, suspended all token minting and redemption activity, asked exchanges and trading venues to halt trading, deposits and withdrawals, and engaged external forensic specialists. It confirmed that the circulating supply of both tokens was not fully backed at the 1:1 ratio required under MiCAR, and said it was notifying the Malta Financial Services Authority of a Major ICT-Related Incident under DORA.
Security firm Blockaid attributed the incident to compromise of a single owner key on the multisig wallet used for minting. CoinDesk, citing GoPlus, reports that wallet was configured with a 1-of-3 threshold, so any one of three authorised owners could approve alone. On Blockaid's account, reported by Cointelegraph, the attacker added their own address as an owner, removed the legitimate signers, then minted about 8.35 million USDR and 4.5 million EURR on Ethereum and sold them into decentralised exchange liquidity for roughly 1,115 ETH, about $2.8 million.
The headline figures in circulation measure different things. The attacker realised roughly $2.8 million, consistent across Cointelegraph and CoinDesk, the gap against face value reflecting heavy slippage in thin pools. The unbacked supply created was larger: Cointelegraph put it near $10.4 million, while CoinDesk reported about $13.5 million at peg. This record uses the realised proceeds as the headline amount and carries the unbacked-supply figure as the upper bound. Both tokens broke their pegs, with CoinDesk quoting USDR at $0.994 and EURR at $0.548 against a euro reference of $1.16.
In a follow-up on 5 June 2026 StablR said the safeguarded reserve assets held before the incident remained segregated from company funds, that minting and redemption were still suspended, and that it was engaging with authorities. It warned holders about third parties offering paid expedited redemption.
Law enforcement
StablR said it would notify the Malta Financial Services Authority of a Major ICT-Related Incident under DORA and file the required MiCAR notifications, and in a 5 June 2026 update said it was in active engagement with the relevant authorities. No arrests reported.
Sources
- StablRPrimary · retrieved 2026-08-01
- StablRPrimary · retrieved 2026-08-01
- Cointelegraph (reporting Blockaid)Secondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
Official post-mortem: https://www.stablr.com/insights/stablr-discloses-cybersecurity-incident-affecting-usdr-and-eurr-token-operations
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "StablR hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/stablrhttps://itokenly.com/hacks/stablrPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.