StablR's EURR and USDR depegged this morning. A 1-of-3 multisig turned out to be one lock short.
The attacker didn't find a code bug. They found a single compromised key in a governance setup that needed only one.

CryptoVibe Desk · stablecoins · exploit · ethereum

- →StablR's EURR fell to $0.88 and USDR fell to $0.70 today after Blockaid detected an exploit tied to a compromised key in the issuer's minting multisig.
- →Regulated stablecoin branding doesn't protect holders when the governance threshold allows one compromised key to rewrite ownership and open the mint without restriction.
- →If StablR doesn't post an on-chain key rotation and a post-mortem within 48 hours, the peg recovery has no credible path.
- multisig → A smart contract that requires approval from multiple private keys before executing an action, meant to prevent any single person from acting alone.
- depeg → When a stablecoin's market price moves away from its target value, meaning one USDR no longer trades for $1.
StablR's EURR fell to $0.88 and USDR fell to $0.70 this morning. Stablecoins aren't supposed to do that.
Blockaid flagged an ongoing exploit tied to a compromised private key. The multisig securing StablR's mint was a 1-of-3 threshold. The attacker changed owner permissions on the contract, then minted 8.35 million USDR and 4.5 million EURR. Cointelegraph reports the attacker swapped about $10.4 million face value through DEXs. That's about $2.8 million total.
This wasn't a smart-contract exploit. Blockaid said the failure was key management and governance. That's the catch. The governance had no floor.
StablR has posted nothing publicly as of this writing. If you're holding EURR or USDR, you're waiting for a statement that hasn't come.
A 1-of-3 threshold with no owner-change time lock isn't a safety net. It's one compromised key away from full mint access. Calling a stablecoin regulated doesn't fix that.
StablR's decision to ship a mint function on a 1-of-3 threshold with no owner-change time lock was a governance failure dressed up as a design choice.
If StablR doesn't publish an on-chain key rotation and a post-mortem within 48 hours, neither peg has a credible recovery path.
Primary links and supporting reads used by the desk for this story.
Forward this.











