$13.5 million. That is the figure sitting in wallets right now as unbacked EURR and USDR — tokens an attacker minted out of nothing by gaining the wrong kind of access to the wrong multisig. The pair depegged within hours, and the on-chain trace went public faster than Stable Labs' own statement did. I have been working through the wallet flows and the disclosure timeline piece by piece. The headline figure is the easy part. The harder question — the one nobody outside a handful of forensic threads has asked yet — is whether the multisig pattern that failed here is also propping up bigger stablecoins that have not yet been tested the same way.

What exactly happened the night EURR and USDR depegged?

The short version: someone with valid signing power on the Stable Labs treasury multisig executed a series of `mint` calls against the EURR and USDR contracts and routed the freshly created supply into liquidity venues before the market understood what was sitting in the pools.

The longer version is a sequencing problem. Mint events on the issuer side and sell events on the venue side happened tightly enough that the depeg printed before the explorer threads had pinned down which contract address was the origin. EURR — the euro-denominated unit — slipped first because its liquidity book is thinner. USDR followed within the same window. By the time the first credible thread had labelled the wallets and tagged the mint transactions, a non-trivial share of the freshly created tokens had already crossed into stable-pair pools and been swapped out into assets the attacker could rotate.

What the public sees now is a peg that has not come back, two contracts where the circulating supply ledger no longer matches the reserves Stable Labs publicly attests to, and a multisig whose threshold turned out to be the entire security model of the system.

How did the attacker get mint authority on the Stable Labs multisig?

Mint authority on EURR and USDR was held by a multisig — the precise threshold and signer set is what every postmortem reader cares about, because the difference between a 2-of-3 and a 4-of-7 is the difference between one compromised laptop and a coordinated operation. Stable Labs' own disclosure is the only authoritative source for the signer geometry, and at the time I am writing this the statement has not pinned the threshold publicly. What the on-chain trace makes unambiguous is that whoever called the mint function had enough valid signatures to clear it. The contract did not get rugged by code — it got walked through the front door.

The mechanics that get you to that point fall into a small number of categories. Compromised private keys on signer devices. Phishing aimed at the operations seat that handles routine treasury rotations. A malicious transaction wrapped to look like a legitimate operational call — the same pattern that hit other treasuries last year — where the signer approves what they think is a parameter change and is in fact authorising fresh supply. Until Stable Labs publishes the device-forensics layer, the public can only narrow the set. The point that matters for everyone else holding stablecoin paper is that the signer set was the single line of defense, and it failed.

Free Download
Crypto Market Cycle Cheat Sheet 2026
Entry signals, exit rules & DCA calculator — based on 3 previous cycles.

Why did $13.5M of unbacked supply break the peg instead of being absorbed?

Because the peg of a small-cap stablecoin is not defended by collateral — it is defended by arbitrage liquidity, and that liquidity is not deep enough to absorb a one-shot shock of this size.

Run the math the way the desk runs it. A stablecoin with a circulating supply in the low nine figures typically holds single-digit-million dollars of top-of-book liquidity in its primary venues. Drop $13.5M of fresh supply into a book like that — even spread across multiple pools — and you exhaust every bid above the danger price within minutes. The remaining bids are reflexive: market-makers stepping away because they cannot reconcile the supply they are seeing on-chain with the reserve attestation the issuer published last month. Once the makers step back, the peg has nothing holding it. The figure for USDC or USDT — backed by something on the order of a hundred billion in deep, regulated reserves and a primary issuance/redemption channel — would absorb $13.5M the way the ocean absorbs a bucket. EURR and USDR cannot. The asymmetry is the whole story.

The order in which the attacker dumped matters too. If they had tried to redeem the freshly minted units through Stable Labs' own issuance gate, the operations team would have caught it within minutes. Liquidity venues do not perform that check. The mint is valid on-chain. The token transfers in. The router swaps. By the time the issuer side is aware, the supply is already distributed across counterparties who did nothing wrong.

Where does the on-chain trail leave the stolen value right now?

Public forensic threads have tagged the originating wallets and traced the downstream hops through the usual constellation of swap routers, bridge contracts, and mixing services. The pattern is the one every CEX security team now expects: rapid fan-out across multiple chains, time-delayed consolidation into wallets that have not been touched in months, and a small fraction routed through tooling specifically designed to break heuristic clustering.

What that pattern produces, in practice, is a set of frozen positions and a set of live ones. Some downstream hops landed on centralized venues whose compliance teams move fast — those balances are paused, sometimes within the same business day. Other hops landed in self-custodial wallets the attacker can sit on indefinitely, waiting for the heat to drop and for newer obfuscation paths to mature. A non-trivial fraction will likely never be recovered, regardless of how thorough the trace is. The recoverable share depends entirely on which exchanges the attacker chose to interact with — and that, in turn, depends on whether they read the same exchange compliance pages I do.

I will not name specific wallet addresses here because the labelling on a piece of stablecoin theft this fresh shifts hour by hour, and citing a tag that gets retracted three days later is worse than citing nothing. The traces are public. Anyone running Etherscan with patience can rebuild the same picture.

Did centralized exchanges freeze the tokens, and which ones moved first?

This is the question where the answer matters more than the headline suggests, because who freezes what, and how fast is the only thing standing between the attacker and clean withdrawal.

The behavioural pattern across the major CEX names is well documented from prior incidents. Binance — daily volume in the $18.5B range and the largest compliance operation in the category — typically freezes implicated deposit addresses within hours of a credible on-chain trace becoming public. Bybit, full VARA-licensed out of Dubai and rated 4.5 on Trustpilot with a $9.2B daily book, runs a similar playbook, often with a public statement attached. OKX, with its Bahamas SCB full licence and Dubai VARA provisional, moves on the same timeline. Bitget and MEXC sit on the slower end — MEXC in particular runs only an offshore Seychelles FSA registration and a partial proof-of-reserves attestation last refreshed 2024-12-10, and historically its freeze responses lag the tier-one venues by a full business day.

For a Stable Labs–scale incident, the realistic recovery window is the first 72 hours. Anything the attacker can route through a venue without freeze cooperation inside that window is functionally gone. The exchanges with stronger compliance programmes are the ones that contain the damage; the venues with thinner programmes are the ones that, by accident or by design, let it through.

Is there a recovery path for holders still sitting on depegged EURR or USDR?

For a holder, the recovery path runs through whatever reimbursement mechanism Stable Labs chooses to publish — and that is the part of every stablecoin failure that nobody pre-commits to until the failure happens.

The three patterns that have played out in prior incidents: a full issuer-funded buyback at par, paid out of treasury reserves the issuer chooses to deploy; a pro-rata haircut, where every holder is made partially whole and the unbacked portion is socialised; or a wind-down, where the issuer freezes redemption entirely and holders are left with a claim against a corporate entity whose ability to pay depends on what the recovery operation actually recoups. Which path Stable Labs will run is not yet public. The choice depends on how much of the unbacked $13.5M they can claw back from frozen exchange addresses, what the legal exposure looks like in the jurisdictions where they are domiciled, and whether they would rather take the balance-sheet hit now or distribute it across the holder base.

For a trader currently holding paper, the practical move is to document the position with on-chain proof of holdings as of the pre-depeg block, watch the official Stable Labs channels for the reimbursement-mechanism announcement, and avoid panic-selling into a thin book at the depegged price unless the haircut already implied by the market is worse than the haircut the issuer is likely to publish.

What does this say about every other small-cap stablecoin run on a multisig?

It says the multisig is not a security model — it is a single point of failure with the operational ceremony of a security model. And that fact applies, today, to almost every stablecoin with circulating supply under a billion.

The defence-in-depth a major issuer runs — bank-grade key custody, hardware-isolated signer ceremony, mint-rate limits enforced at the contract level, time-locked supply changes, off-chain attestation that has to clear before any new tranche unlocks — costs real money to operate. A small issuer cannot justify the spend until the supply grows. So the small issuer ships with a 3-of-5 multisig held by founders and operations leads, calls that "decentralised governance" in the marketing copy, and prays the threshold never gets compromised. The pattern works until it does not.

Run the test on any stablecoin you currently hold. Is the mint authority a multisig? What is the threshold? Are the signers identifiable, and if they are, can you map them to real custody arrangements? Is there a contract-level rate limit on supply changes? Is there a time delay between a mint being authorised and the supply actually crediting? For most small-cap units, the answers are: yes / low / no / no / no. EURR and USDR were not anomalies. They were a category.

How should a trader actually check the issuer side of a stablecoin before holding it?

Three things, in this order.

First, reserve composition versus circulating supply, refreshed at least monthly. The attestation should name the custodians holding the reserve assets, the auditor reviewing the attestation, and the exact composition by asset class. "Cash and cash equivalents" is not a composition — it is a vibe. If the issuer cannot show you which bank holds the cash and which auditor signed off, the attestation is theatre. Proof of reserves without liabilities is theatre, and proof of reserves without auditor identity is worse than nothing.

Second, mint authority topology. Read the contract. Identify the address that can call mint. If it is a multisig, identify the threshold and, if possible, the signers. If there is no rate limit and no timelock, treat every dollar of supply as a position you are taking on the security of that signer set — because that is, mechanically, what it is.

Third, venue concentration and exit liquidity. If 80% of the circulating supply lives in two AMM pools whose combined depth is less than the supply you are holding, the peg you are relying on cannot defend itself against any meaningful shock. EURR and USDR depegged on $13.5M of unbacked supply. Whatever amount would break the peg of the stablecoin you currently hold is a number you can calculate, and probably should.

Is the Stable Labs failure mode something a bigger issuer could repeat?

The clean answer: probably not in this exact form, because the bigger issuers do not concentrate mint authority on a single multisig and do not lack the rate limits that would have throttled this attack to a containable size. The honest answer: the bigger issuers concentrate risk in different places, and the next stablecoin failure of this scale will look nothing like this one — it will look like whatever the bigger issuers chose to skimp on instead.

The Stable Labs failure was a signer-set failure. The next one will probably be a custodian failure (the reserves are real but the bank holding them isn't), an attestation gap failure (the auditor signed off on a snapshot that was already three weeks stale), or a rehypothecation failure (the assets in the reserve are not actually unencumbered, and the issuer's counterparties have claims on them). Each of those is harder to detect from on-chain data alone. Each of those would also produce a depeg that nobody can fix with a multisig rotation.

So the lesson from EURR and USDR is not "audit the multisig". It is broader than that. Every stablecoin sits on a stack — contract layer, issuer operations layer, custodian layer, attestation layer, redemption layer — and the unit is only as strong as the thinnest of those five. Stable Labs' thin layer was the contract layer. For the next issuer it will be a different layer. The traders who survive the next event will be the ones who already mapped the stack on the units they hold.

Whether the bigger issuers have done that mapping rigorously enough to survive a sophisticated, targeted attack on their thinnest layer — and whether the proof-of-reserves regimen the industry has converged on actually measures the right surface — is a question I do not think anyone in the public data has answered yet. If you have run the trace on a major issuer and can show me the thinnest layer, write.

FAQ

How much unbacked EURR and USDR is actually circulating right now?

The figure being cited across forensic threads is $13.5 million in aggregate across both tokens, minted in the exploit window and not backed by any corresponding reserve increase on the Stable Labs side. The split between EURR and USDR has not been published with precision by the issuer, but the depeg behaviour — EURR slipping first and harder — suggests the euro-denominated unit took the larger share of the unbacked supply relative to its market cap. Until Stable Labs publishes a reconciled supply ledger, treat the $13.5M as the aggregate envelope.

Can I still sell EURR or USDR on exchanges after the depeg?

On some venues yes, on others no — and the answer is changing by the hour. CEX names with stronger compliance programmes typically halt deposits and pause withdrawals on the affected tokens once a credible exploit trace is public. Spot trading sometimes stays open at the depegged price; sometimes it gets suspended entirely. DEX pools remain accessible by definition, but the liquidity is thin and the slippage on any meaningful size is severe. Check the official venue announcement before assuming the pair you traded yesterday is still tradable today.

Will Stable Labs reimburse holders at par?

That decision is the issuer's, and at the time I am writing this it has not been published. Historical precedent in stablecoin failures runs from full issuer-funded buybacks at par, to pro-rata haircuts, to total wind-downs with holders left as creditors. Which path Stable Labs runs depends on how much they recover from frozen exchange addresses, what their treasury position can absorb, and what their legal counsel recommends in the jurisdictions where they operate. Watch the official statement, not the forum speculation.

Is this the same as the Terra/UST collapse?

No. UST was an algorithmic stablecoin that lost its peg because its stabilisation mechanism — burn and mint against a paired asset — failed under reflexive pressure. EURR and USDR are reserve-backed units that depegged because $13.5M of supply got created without corresponding reserves. UST was a design failure. This is an operational security failure. The remediation paths are different: UST could not be fixed because its mechanism was broken; EURR and USDR can in principle be fixed if Stable Labs can absorb the loss and rotate the compromised multisig.

What is a multisig exploit in plain terms?

A multisig is a contract that requires multiple signatures — say, three out of five — to execute a privileged action like minting new supply. A multisig exploit means an attacker gained valid signing power from enough of those signers to clear the threshold. That can happen through compromised private keys, social engineering against the signers, or a malicious transaction wrapped to look like a routine operation. The contract behaves correctly; the security model fails at the human layer.

Should I move my stablecoins to a regulated US-based issuer like Coinbase's USDC partnership?

"Regulated" reduces some categories of risk and not others. A US-supervised issuer with a FinCEN MSB and a NYDFS BitLicense — Coinbase falls in that bracket — gives you stronger reserve attestation discipline, clearer redemption rights, and an enforcement layer if the issuer misbehaves. It does not eliminate custodian risk, sanctions risk, or the risk that the regulatory regime itself changes. Larger, regulated issuers are the safer category for most holders. They are not zero-risk; they are differently-risked.

How long before exchanges fully delist EURR and USDR?

Most venues run a sequence: halt deposits, halt new orders, leave existing orders open for a window, then full delist. The window varies from days to weeks. Tier-one venues like Binance, Bybit and OKX typically publish the timeline in their official notice. Smaller venues sometimes delist with little or no notice. If you hold the tokens on a CEX, move them off (if withdrawals are still enabled) before the venue's delisting clock starts, or accept the venue's wind-down process, which is rarely favourable to the holder.