StablR said on May 24, 2026 that an exploit had affected its platform, while blockchain-security firm Blockaid reported that unauthorized minting had pushed the issuer’s euro and dollar stablecoins away from their intended pegs. The incident placed an operational failure inside the perimeter of a European issuer authorized to issue electronic-money tokens under the Markets in Crypto-Assets Regulation.
The event mattered because the promise behind a fiat-referenced token is not only that reserve assets exist. Holders also depend on the issuer’s controls over minting, redemption and administrative keys. On May 24, that control layer failed: tokens could be created outside the authorized issuance process, and confidence in the one-for-one backing of the circulating supply broke with it.
What was known on May 24
StablR’s event-day message was brief. The company said it had identified an exploit and was working to contain it and minimize the impact. It did not publish a final loss figure, a root-cause report or a recovery schedule on May 24.
Blockaid’s contemporaneous alert supplied the first technical account. The security firm said one key controlling a one-of-three multisignature wallet appeared to have been compromised. Because the wallet required only one signature, the attacker could add a new owner, remove the other owners and obtain control of minting. Blockaid characterized this as a key-management and governance failure, not a defect in the stablecoin token code itself.
Blockaid estimated that 8.35 million USDR and 4.5 million EURR had been minted and that sales into decentralized exchanges returned about 1,115 ETH, valued by the firm at roughly $2.8 million at the time of its May 24 alert. Those were preliminary incident-response estimates, not audited losses. The face value of newly minted tokens, the value actually extracted, and the issuer’s ultimate liability are different measurements. Thin liquidity meant that selling a larger nominal amount did not produce an equal amount of proceeds.
Both USDR and EURR traded below their target values during the incident. Coinburn does not assign a single depeg percentage because contemporaneous trackers captured different pools and times in a continuously traded market. The verified market fact is the loss of parity observed on May 24, not a universal closing price across venues.
The backing problem became explicit
In a company announcement dated May 25, StablR confirmed that it had identified irregularities on May 24 consistent with unauthorized external access and had immediately suspended all minting and redemption. The issuer said the circulating supplies of USDR and EURR were no longer fully backed at the one-to-one ratio required under MiCA. It also asked listed exchanges and trading venues to halt trading, deposits and withdrawals.
That statement sharpened the institutional significance of the attack. A reserve attestation can describe assets held against valid issuance, but it cannot by itself prevent an attacker with administrative authority from creating additional claims. The incident therefore exposed the connection between cybersecurity controls and the credibility of regulated token money.
StablR said it would notify Malta’s financial regulator as a major information-and-communications-technology incident under the Digital Operational Resilience Act, make the required MiCA notifications, engage outside forensic specialists and report the matter to law enforcement. Those were announced response steps, not findings that regulators had completed an investigation.
Later context
On August 25, 2026, after receiving forensic and blockchain-intelligence findings, StablR said the attack spanned May 23 and May 24 and that approximately 14.33 million unauthorized USDR and 6.41 million unauthorized EURR remained in circulation. It said properly issued tokens remained backed by segregated reserves and that no further unauthorized minting had occurred.
Those later totals superseded the preliminary scale estimates available on May 24, but they do not change the event-day conclusion: a compromised issuance-control system created unbacked tokens, broke both pegs and forced the issuer to stop core operations. Open questions on May 24 included how the key was compromised, why a one-signature threshold controlled minting, how holders would be treated and when redemptions could resume.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

