StablR's EURR and USDR Stablecoins Depeg After Multisig Exploit
Regulation

StablR's EURR and USDR Stablecoins Depeg After Multisig Exploit

05 Sep 2026, 18:30 4 views Admin

The Tether- and Kraken-backed European stablecoin issuer StablR saw its EURR and USDR tokens lose their pegs after an attacker took control of its minting contract and printed $13.5 million in unbacked tokens.

<p>Stablecoins issued by StablR, a European stablecoin issuer backed by Tether and Kraken, lost their pegs after an attacker gained administrative control of the issuer's minting contract and printed approximately $13.5 million in unbacked tokens before dumping them on decentralized exchanges. Both EURR, the issuer's euro-denominated token, and USDR, its dollar-denominated stablecoin, were affected by the exploit, which unfolded over a Saturday night into Sunday morning.</p>
<p>The attack exploited a multisig vulnerability rather than a novel smart contract bug, giving the attacker administrative-level minting privileges that allowed them to create tokens far beyond what the issuer's actual reserves could back. Once minted, the attacker sold the excess unbacked tokens on decentralized exchanges, flooding the market with supply that broke the tokens' price peg to their respective underlying fiat currencies.</p>
<p>The StablR incident fits a broader pattern that has defined 2026's costliest crypto exploits: privileged-access, governance, and key-management failures, rather than novel smart contract bugs, have driven the year's most damaging attacks. That pattern has held across multiple major incidents throughout the year, from DeFi protocol exploits to, now, stablecoin issuer compromises, suggesting attackers have increasingly focused on exploiting administrative and access-control weaknesses rather than searching for previously unknown code vulnerabilities.</p>
<p>The incident adds to a difficult year for stablecoin stability more broadly, following earlier depeg events including Resolv Labs' USR stablecoin collapsing more than 95% in March after an exploit, and Abracadabra's Magic Internet Money falling 50% below its dollar peg in June, prompting emergency measures from the protocol. Each incident has reinforced ongoing concerns about the security infrastructure underlying various stablecoin issuance models, even as the broader stablecoin sector has posted record transaction volumes throughout 2026.</p>
<p>For StablR specifically, the backing from established players like Tether and Kraken gives the issuer meaningful institutional credibility that could support recovery efforts, though the incident nonetheless raises questions about the administrative access controls protecting even backed, institutionally-supported stablecoin projects. As stablecoin transaction volumes continue climbing to record levels globally, incidents like the StablR exploit underscore that scale and institutional backing alone do not eliminate the operational security risks facing stablecoin issuers.</p>
Share