StablR Bleeds $2.8M as Euro and Dollar Stablecoins Lose Their Peg

StablR Bleeds $2.8M as Euro and Dollar Stablecoins Lose Their Peg

A single compromised private key inside a minting multisig brought two regulated stablecoins to their knees — and exposed a recurring fault line in DeFi security architecture.

Written by OutOfToken AI

May 31, 2026 · 4 min read · Synthesized from reporting by CoinTelegraph · How this works

AI Likely Accurate · 7/10

StablR, the issuer behind euro- and USD-denominated stablecoins, is fighting an active exploit that has drained approximately $2.8 million and sent both tokens sliding from their intended 1:1 pegs. Blockchain security firm Blockaid traced the root cause to a private key compromise affecting one owner within the protocol's minting multisig account. What should have been a distributed, fault-tolerant signing mechanism became the single point of failure that attackers needed.

How a Multisig Became a Single Point of Failure

Multisignature wallets are designed precisely to prevent this kind of catastrophe — requiring multiple independent keyholders to authorize sensitive operations like minting new supply. In theory, compromising one participant should not be enough to move funds or inflate token supply unilaterally. In practice, the security guarantee is only as strong as the threshold configuration and the operational security of each individual keyholder. If a multisig is configured as a 1-of-N or even a low-threshold M-of-N scheme, one leaked or stolen private key can grant an attacker sufficient signing authority. Blockaid's preliminary analysis suggests that is precisely the scenario that unfolded at StablR, where a single owner's key exposure appears to have unlocked minting privileges the attacker immediately weaponized.

The Mechanics of a Stablecoin Depeg Under Attack

Once an attacker gains minting access, the playbook is straightforward and brutal. Unauthorized tokens are minted, dumped into liquidity pools or sold on secondary markets, and the sudden supply surge overwhelms demand — collapsing the price below the pegged value. Both StablR's euro-denominated stablecoin and its USD-pegged counterpart experienced visible depegging as the exploit progressed, rattling confidence across the platforms and pools where the tokens circulate. The $2.8 million figure reflects assets extracted during the attack window, though depegging events carry secondary damage well beyond the direct drain: liquidity providers face impermanent loss, arbitrageurs scramble, and ordinary holders watch the supposed stable value of their holdings erode in real time.

""A single compromised key inside a minting multisig was enough to extract $2.8 million and break the peg on two separate stablecoins simultaneously." — Blockaid's post-incident attribution"

A Pattern the Industry Refuses to Fix

Private key compromises in multisig configurations are not novel. They represent one of the most consistently documented and consistently underestimated attack vectors in decentralized finance. High-profile protocol hacks stretching back years have traced back to the same failure mode — inadequate key management hygiene, insider threats, phishing campaigns targeting signers, or infrastructure vulnerabilities exposing key material. The stablecoin sector carries an additional layer of systemic risk because its products are explicitly marketed as safe harbors. When a stablecoin depegs, the damage is not just financial but reputational, undermining the core value proposition that distinguishes stablecoins from volatile crypto assets. StablR's incident arrives at a moment when euro-denominated stablecoins are gaining regulatory traction under the EU's MiCA framework, making security failures particularly consequential for the sector's institutional ambitions.

StablR's exploit is still live at the time of reporting, and the full damage assessment remains incomplete. What is already clear is that the DeFi industry's relationship with multisig security needs a serious recalibration — stricter threshold requirements, hardware security modules for key storage, and continuous monitoring of signing authority activity are not optional hardening measures, they are baseline requirements for any protocol with the audacity to promise stability. Until issuers treat key management with the same rigor as smart contract audits, events like this will keep repeating, and the stablecoins caught in the crossfire will keep falling.

Editorial Note

CoinTelegraph is a reputable cryptocurrency news outlet with established fact-checking practices. The claim about private key compromise in multisig accounts is a plausible and commonly documented vulnerability in DeFi protocols. Blockaid is a recognized blockchain security firm that regularly investigates exploit incidents, lending credibility to their attribution.

Claim Tracker

AI-assessed

UnverifiedStablR drained approximately $2.8 million

Specific figure not independently confirmed; relies on Blockaid's analysis

UnverifiedBlockchain security firm Blockaid traced the root cause to a private key compromise of one owner in the minting multisig account

Attribution to Blockaid is stated but their analysis methodology and evidence are not detailed in excerpt

UnverifiedBoth euro- and USD-denominated stablecoins lost their 1:1 pegs

The extent and duration of de-pegging is not specified

VerifiedMultisignature wallets require multiple independent keyholders to authorize sensitive operations like minting

This is accurate technical description of multisig functionality

VerifiedA 1-of-N or low-threshold M-of-N multisig configuration allows one compromised key to grant sufficient signing authority

Technically accurate description of multisig threshold risks

Ask AI about this story

// discussion

sign in to join the discussion