25 August 2026

Notification — August 25th

To our community and token holders,

This is a further update following our previous notices regarding the cybersecurity incident of 24 May 2026 affecting EURR and USDR.

Since the incident, StablR has received the relevant investigative, forensic and blockchain-intelligence findings, completed an internal review and implemented a number of remediation measures. We are now able to share further factual information about the nature and impact of the incident.

What happened

Between 23 and 24 May 2026, StablR was the target of a criminal cyber-attack. An external, unauthorised third party gained access to part of the infrastructure and used that access to create (“mint”) EURR and USDR tokens outside StablR’s authorised issuance process. These tokens were created without StablR’s authorisation and without any corresponding payment of funds.

As a result of this unauthorised activity, approximately 6.41 million EURR and 14.33 million USDR of unauthorised tokens are currently in circulation. Because these tokens were created outside our issuance process and against no payment, they are not backed by reserve assets. EURR and USDR that were properly issued by StablR against payment continue to be fully backed.

StablR engaged independent forensic and blockchain-intelligence specialists to investigate the incident and trace the movement of the unauthorised tokens, and continues to cooperate with the relevant regulatory and law-enforcement authorities.

Status

There has been no further unauthorised minting since the incident, and the incident remains contained.

As a precaution, minting and redemption of EURR and USDR remain temporarily suspended. StablR activated its Recovery Plan following the incident and continues to work with the Malta Financial Services Authority and its professional advisers on the appropriate regulatory and operational next steps, including the orderly resumption of services in due course.

Reserve assets

The reserve assets backing lawfully issued EURR and USDR are held in segregated accounts, separate from StablR’s own funds, in accordance with MiCAR. Based on the information available to date, these safeguarded assets were not affected by the incident and remain intact.

Remediation

Following the investigation and internal review, StablR has implemented a number of measures to strengthen its security and operational controls. These measures are intended to address the matters identified through the post-incident review and to reduce the risk of recurrence.

What this means for token holders

We understand token holders will want to know what this means for them. Lawfully issued EURR and USDR remain backed by segregated reserve assets. While minting and redemption are temporarily suspended, StablR is working to enable an orderly resumption under the supervision of the MFSA, and will keep holders informed as matters progress. StablR is not able to comment on individual transactions or on matters that remain subject to ongoing investigation.

Protecting yourself against fraud

Token holders are reminded to rely only on StablR’s official communication channels. StablR will never request your private keys, seed phrases, passwords or any payment. Any communication making such a request should be treated as potentially fraudulent and reported. For incident-related queries, please contact info@stablr.com.

We recognise the importance of clear and transparent information to our community and token holders. StablR will continue to communicate material developments affecting EURR and USDR through the Insights section of its website and its official social-media channels, including X, as appropriate.