Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Regulations & Policies

Can MiCA Prevent Multisig Hacks? StablR’s $10M Exploit Exposes the Gap

StablR holds an EMI license from Malta's MFSA, operates under MiCA, and is backed by Tether and Kraken — yet its minting infrastructure used a weaker multisig setup.

Written By Dhara Chavda
Published 2026-05-25·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Can MiCA Prevent Multisig Hacks? StablR's $10M Exploit Exposes the Gap
Show AI Summary
Poor key management led to StablR’s compromise via a breached private key
A single compromised key was enough to exploit the 1-of-3 threshold multisig
Inadequate governance allowed the attack to continue unchecked for over three hours

StablR—Malta-headquartered, EMI-licensed, MiCA-regulated, backed by both Tether and Kraken—was supposed to be a poster child for Europe’s regulated stablecoin future. But now it became the latest protocol drained through one of the most preventable attack vectors in crypto.

Onchain investigator ZachXBT flagged the exploit first, posting to his investigations channel that two contracts tied to StablR’s euro-pegged EURR and dollar-pegged USDR appeared compromised. He identified the attacker’s primary wallet (0xea480c23d7b29a515856aafe0dc86f7519965a04), noted it had been funded via the Cross-Chain Transfer Protocol (CCTP) on Noble, and listed seven additional addresses linked to the same incident.

The mechanics were blunt. Blockchain security firm Blockaid attributed the breach to a compromised private key tied to StablR’s minting multisig—not a smart contract vulnerability. The multisig operated under a 1-of-3 threshold. One key was enough. The attacker added their own address as an owner, removed the two legitimate signers, then minted 8.35 million USDR and 4.5 million EURR — roughly $10.4 million in unbacked tokens at peg.

Suspected Root cause: Private key compromise of a minting multisig owner.

The @StablREuro minting multisig had a 1-of-3 threshold – a single compromised key was enough for full control. The attacker:

1. Added themselves as owner
2. Replaced the other 2 legitimate owners
3.…

— Blockaid (@blockaid_) May 24, 2026

EURR fell approximately 39% to $0.7. USDR crashed to as low as $0.40. Thin DEX liquidity limited the attacker’s actual haul to roughly 1,115–1,488 ETH ($2.8M–$3.15M), but the reputational damage extends far beyond the dollar figure.

Blockaid’s follow-up was direct: “This is not a smart contract bug — it’s a key management and governance failure.”

ZachXBT Steps In, StablR Stays Silent

About two hours after his initial alert, ZachXBT posted that he had helped freeze six figures in stolen funds. He then noted the StablR team appeared to be “asleep” while the attack continued for over three hours after being publicly flagged.

StablR acknowledged the exploit — roughly eight hours after onchain activity on the affected contracts had stopped. The company said it had “identified an exploit affecting the protocol” and was working to contain the impact. No recovery plan has been announced at the time of publication.

What MiCA Actually Covers — and What It Doesn’t

This is where the story gets uncomfortable for European regulators.

StablR checked every box the EU’s Markets in Crypto-Assets Regulation asks stablecoin issuers to check. It holds an Electronic Money Institution (EMI) license from the Malta Financial Services Authority (MFSA). It issues tokens backed by fiat and short-term government bonds in segregated accounts. It publishes a whitepaper. It raised €3.3 million in seed funding from Deribit, Maven 11, Theta Capital, Folkvang, and Blocktech, then secured strategic investments from Tether (December 2024) and Kraken (July 2025). By July 2025, it reported €3 billion in transaction volume across 50+ exchanges and 150+ trading pairs.

None of that prevented a 1-of-3 multisig from being the single point of failure controlling its entire minting infrastructure.

MiCA’s requirements for EMT issuers are heavy on reserves, disclosures, redemption rights, and AML/KYC obligations. It mandates governance structures and “operational resilience.” But the regulation does not prescribe specific technical standards for private key management, multisig thresholds, or onchain access controls. It does not require a minimum number of signers on a minting contract. It does not audit the security architecture that stands between a compromised key and unbacked token issuance.

The EU’s Digital Operational Resilience Act (DORA), which became applicable in January 2025, is supposed to complement MiCA by addressing ICT risk management and cybersecurity for financial entities, including CASPs. But DORA’s framework is designed around traditional IT resilience — incident reporting, business continuity, third-party risk management—not the specific attack surface of onchain governance. A 1-of-3 multisig on a minting contract is not the kind of vulnerability DORA was built to catch.

For context: Harmony’s Horizon bridge used a 2-of-5 multisig before being drained for $100 million in 2022. Security analysts had already characterized that setup as insufficient at the time. StablR’s 1-of-3 configuration was objectively weaker — and this was a licensed, regulated issuer operating in 2026.

A Pattern That’s Bigger Than StablR

The exploit fits a recurring 2026 pattern. The costliest incidents this year have not been driven by novel smart contract bugs. They have been driven by privileged-access, key-management, and governance failures at the operational layer.

The $280 million Drift Protocol exploit in April — which also routed proceeds through Circle’s CCTP — was attributed to compromised administrative access. The $80 million Resolv Labs USR exploit in March used near-identical mechanics: a single insufficiently protected key enabling unauthorized minting at scale. MAP Protocol, Echo Protocol, THORChain, and Verus Bridge have all suffered exploits tied to private or admin-key access in the past two months alone.

April was the most-hacked month in crypto history by incident count, according to DefiLlama. May is continuing the trend.

The industry has gotten significantly better at auditing smart contract code. What it has not gotten better at — and what MiCA does not meaningfully address — is the operational security layer that sits between the code and the humans who control it.

The Bigger Problem for Europe’s Stablecoin Ambitions

StablR was not a random DeFi experiment. It was Tether’s strategic proxy in Europe after Tether wound down its own euro stablecoin, EURT, ahead of MiCA’s December 2024 deadline. Kraken’s investment further validated StablR’s position as a key piece of Europe’s regulated stablecoin infrastructure. The company uses Tether’s Hadron tokenization platform and had been actively pitching itself to institutional and enterprise clients.

That positioning makes the 1-of-3 multisig choice harder to explain and harder for regulators to dismiss. If a company at the center of Tether’s European strategy, listed on 50+ exchanges, processing billions in volume, can secure its minting function with the weakest possible multisig configuration — and still maintain full regulatory standing — the framework has a gap.

The question for European regulators is no longer hypothetical. MiCA was built to prevent the next Terra/LUNA. It was not built to prevent the next StablR. Whether the MFSA, ESMA, or the EBA moves to address that gap — by mandating minimum key management standards, requiring third-party security audits of onchain governance architecture, or tightening operational resilience requirements under DORA — will determine whether MiCA remains a reserves-and-disclosure framework or evolves into something that actually covers the full risk surface of stablecoin issuance.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Polkadot Launches Native dotUSD Stablecoin Through OpenGov
Polkadot Launches Native dotUSD Stablecoin Through OpenGov
STRK Price Rises 19% as Starknet Targets Quantum-Resistant L1 by 2027
NFL shield logo, Kalshi smartphone screen, and a judge's gavel set before the Supreme Court building.
NFL Urges Supreme Court to Review Kalshi Sports Contracts
Physical Zcash (ZEC) coin standing in front of a red declining market chart.
Zcash (ZEC) Price Falls 13% as Open Interest Drops and ETF Outflows Rise
Physical Bitcoin and Ethereum coins standing against a red declining financial chart.
Bitcoin Falls 3.3%, Ethereum Drops 5.7% as Crypto Selloff Deepens

Find Us on Socials

You may also like

Hand holding a smartphone displaying the Coinbase logo against a Coinbase background.

Coinbase Appeals Connecticut Ruling Over Sports Event Contracts

Cryptocurrency coins beside a legal gavel and prohibition sign, framed by UK and Russian landmarks.

UK Widens Russia Sanctions With New Crypto Exchange Targets

Handcuffed suspect standing before a table with SIM cards, smartphone, and Bitcoin in London.

UK Court Jails Man in Nearly £200K Crypto SIM-Swap Case

European Securities and Markets Authority (ESMA) signage with Tether stablecoin coins and European Union flag.

ESMA Sets Three-Month Deadline for EU Firms With Non-MiCA Tokens

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information