StablR: EFRI asks MFSA what became of its 2025 ‘exhaustive analysis’
One year after the Malta Financial Services Authority told EFRI that it was conducting an “exhaustive analysis” of concerns surrounding StablR Ltd, EFRI has returned to the regulator. Two significant developments make renewed scrutiny necessary: the May 2026 StablR cyber incident and substantially new evidence concerning the Payvision management environment.
In July 2025, EFRI formally asked the MFSA to reassess StablR’s EMI licence, raising questions about its management, ownership and the Payvision history of key executives. Our original concerns are set out here:
EFRI urges MFSA to review StablR’s EMI Licence
On 1 August 2025, the MFSA responded that it was “currently undertaking an exhaustive analysis of the contents of the letter and any implications on the relevant licensed entity.” (Up to today the DNB rejects claims from Payvision’s victims to hand over the report).
EFRI had specifically urged the MFSA to obtain and review the September 2020 DNB supervisory report on Payvision when assessing the fitness and properness of StablR’s senior management.
We have not been informed of the outcome of the MFSA’s announced analysis.
Two significant developments since then
First, on 24 May 2026 StablR suffered a serious cyber incident affecting EURR and USDR. StablR acknowledged that its circulating tokens were no longer fully backed at the 1:1 ratio required under MiCAR and suspended minting and redemption.
EFRI examined the incident, the reported 1-of-3 minting-authority configuration, StablR’s intragroup technology structure and the regulatory questions arising under MiCAR and DORA in our earlier analysis:
StablR Cyber Incident: What Did the MFSA Supervise?
Redemption remains suspended approximately three months after the incident. EFRI is now asking the MFSA to clarify the legal and supervisory basis for that continuing suspension, whether the conditions for a MiCAR Redemption Plan have been assessed and whether partial or pro-rata redemption could be implemented.
Second, the evidence concerning Payvision has changed materially.
On 15 May 2026, EFRI completed an extensive review of criminal files, payment records, merchant agreements and internal communications concerning Payvision’s role in the Barak and Lenhoff fraud networks. The resulting report documents payment infrastructure serving fraud schemes that affected more than 60,000 European consumers and caused losses estimated at approximately €340 million.
EFRI’s Full Payvision Report: When Payment Infrastructure Becomes Fraud Infrastructure
The report also provides substantially more detailed evidence concerning the management environment in which StablR CEO Gijs op de Weegh and Chief Risk and Operations Officer Corné van der Meijden previously operated.
EFRI does not claim that the Payvision history caused the StablR cyber incident. They are separate events.
But both raise legitimate supervisory questions about governance, controls, management oversight, risk culture and soundness of judgement.
So what became of the MFSA’s analysis?
EFRI has therefore submitted today a renewed supervisory request to the MFSA, with the European Banking Authority copied.
Among other things, we are asking whether the MFSA’s “exhaustive analysis” announced in August 2025 was ever concluded, whether it obtained and considered the DNB supervisory report as specifically requested by EFRI, and whether the new Payvision evidence and the subsequent StablR control incident have caused that assessment to be reopened or updated.
We are also asking the MFSA to address the protection of EURR and USDR holders and the continuing suspension of their redemption rights.
The question is no longer simply what the MFSA examined when it licensed StablR. It is what the Authority concluded from the concerns raised in 2025 – and whether the events and evidence that have emerged since then have changed that conclusion.
Why StablR matters to EFRI
For readers unfamiliar with StablR, this is not just another crypto start-up. StablR is a post-Payvision financial venture founded and managed by former senior Payvision executives. Officially it is CEO Gijs op de Weegh co-founded Payvision and served in its senior management, while StablR’s Chief Risk and Operations Officer Corné van der Meijden was Payvision’s CFO.
Payvision provided payment infrastructure to the Barak and Lenhoff fraud networks through which tens of thousands of European consumers lost enormous sums – in many cases their life savings. Many of those victims are still fighting for compensation today.
After Payvision ceased operations in 2022, StablR was established in Malta and, in June 2024, the MFSA granted it an Electronic Money Institution licence.
That history is why StablR’s governance and the MFSA’s supervisory assessment matter to EFRI.







