
Blockchain security firm Blockaid detected an ongoing exploit affecting StablR stablecoins on Ethereum, resulting in the depeg of both EURR and USDR tokens. According to Blockaid, the attacker targeted the issuer behind StablR Euro (EURR) and StablR USD (USDR), extracting approximately $2.8 million in the process. The suspected cause was a compromised private key linked to one owner of the minting multisig account, which reportedly used a 1-of-3 threshold setup where one compromised owner key was sufficient to control minting access. The attacker added themselves as an owner, replaced the two other legitimate owners, and minted 8.35 million USDR plus 4.5 million EURR tokens, effectively depegging the two tokens from their $1 parity bands. On-chain investigator ZachXBT has now flagged a $3 million exploit targeting the stablecoin issuer, which appears to have triggered the pricing dislocation between StablR's two tokens.
The suspected exploit has caused a complete breakdown in the expected correlation between StablR's two stablecoins, with EURR falling 20% in a sharp move that saw USDR decouple from EURR, breaking the expected pricing relationship. In plain terms, "decoupling" means the two assets stopped moving in the correlated pattern that traders and liquidity providers had come to expect. Stablecoins are designed to hold a narrow trading range against their reference currency, and a 20% deviation in EURR represents a breakdown in the mechanisms that keep the token near its peg. The decoupling suggests that traders and arbitrageurs priced in distinct risk for each token rather than treating StablR's products as uniformly affected. EURR trading near $0.88 on CoinGecko, down more than 23% over 24 hours, while USDR also traded below its intended $1 peg during the incident, with CoinMarketCap listing the token near $0.70. The depegging has raised questions about liquidity depth, reserve sufficiency, and the speed with which stablecoins can respond to coordinated governance- or key-management failures.
The attacker then swapped approximately $10.4 million in face value through decentralized exchanges, realizing only 1,115 ETH worth about $2.8 million due to thin liquidity conditions. According to Blockaid, this represents a key management and governance failure rather than a smart contract bug. The perpetrator exploited a weak key-management arrangement within the minting multisig, then assumed control of the three-key setup by replacing the other owners. The newly minted tokens were subsequently liquidated on decentralized exchanges for approximately 1,115 ETH, translating to around $2.8 million in proceeds given current liquidity conditions. The exploit can freeze liquidity and block normal arbitrage flows, allowing prices to drift far from par. When an exploit is suspected, liquidity providers commonly pull funds from associated pools as a precaution, draining the order book depth that normally keeps spreads tight between related tokens. With fewer market makers willing to quote EURR, any sell pressure gets amplified, as a token that might normally absorb a $100,000 sell order with minimal slippage can gap down sharply when liquidity evaporates.
StablR presents EURR and USDR as regulated stablecoins backed by reserves held in secure segregated accounts at top-tier institutions, with both tokens running on Ethereum and Solana and pegged to the euro and U.S. dollar for digital transactions. The issuer has been part of Tether's European stablecoin push, with Tether investing in StablR in December 2024, while crypto.news reported that Oobit and StablR launched MiCA-compliant EURR and USDR payment support in Europe. The project emphasizes reserves held in segregated accounts at established institutions, along with proof-of-reserves and cross-chain availability on Ethereum and Solana. StablR maintains a proof-of-reserve page, though the degree to which reserves were affected by the suspected exploit remains unclear. The immediate question is whether EURR can recover its peg or whether the deviation deepens, with price recovery within hours or days suggesting the exploit's impact was contained.
The incident sits within a wider tapestry of security breaches this year that center on compromised keys and governance weaknesses. A sequence of recent exploits—Volo Vault, Wasabi Perps, Echo Protocol, and Polymarket—have all involved some manipulation of admin or private keys. Analysts warn that as DeFi ramps up, so do the attack surfaces tied to governance and access management. The broader question remains whether the industry will tighten the screws on key management fast enough to prevent similar breaches from repeating across the expanding DeFi frontier. Industry observers argue that improving multi-party computation, hardware-backed key storage, formalized incident-response playbooks, and enhanced rotation and revocation protocols will be essential as protocols grow larger and more interconnected. The market remains vigilant for how quickly teams can respond to breaches, how robust their reserve disclosures remain, and what steps are taken to prevent recurrence, with May's incidents potentially accelerating adoption of best practices around governance hygiene, key security, and incident preparedness.