StablR confirms more than 20 million unbacked token units remain in circulation
StablR has for the first time quantified the unauthorised EURR and USDR tokens still in circulation. According to the issuer, 6.41 million EURR and 14.33 million USDR of unauthorised tokens remain in circulation without corresponding reserve assets. The disclosure came one day after EFRI submitted a detailed supervisory request to the Malta Financial Services Authority, copied to the European Banking Authority, concerning the May cyber incident, the continuing suspension of redemption and unresolved questions under MiCAR.
As long as more than 20 million unbacked token units remain in circulation, the potential for further consumer harm remains: subsequent purchasers may acquire EURR or USDR without knowing whether StablR considers the tokens they hold to carry an enforceable redemption claim.
On 24 August 2026, EFRI submitted a renewed supervisory request concerning StablR Ltd to the Malta Financial Services Authority (MFSA), copied to the European Banking Authority (EBA) (pls read here the full letter). The submission followed the cyber incident of 24 May, after which StablR suspended minting and redemption and acknowledged that the circulating supply of EURR and USDR was no longer fully backed at the required 1:1 ratio.
EFRI asked the MFSA to clarify the technical and regulatory consequences of the incident, the continuing suspension of redemption, the status of StablR’s Recovery Plan and the supervisory assessment of the company’s controls and management.
On 25 August, StablR published its most detailed notification to date.
The timing does not establish that StablR’s disclosure was prompted by EFRI’s submission. It does, however, mean that several information gaps expressly identified by EFRI only one day earlier have now partly been addressed.
StablR now quantifies the unauthorised issuance
StablR states that approximately 6.41 million EURR and 14.33 million USDR of unauthorised tokens are currently in circulation. According to the company, these tokens were created without corresponding payment and are therefore not backed by reserve assets.
This is an important new disclosure. In its 24 August submission, EFRI had specifically pointed out that StablR had not published a technical post-mortem confirming or correcting the earlier Blockaid analysis and had not quantified the remaining shortfall. EFRI also asked whether the MFSA had examined the reported 1-of-3 minting threshold, segregation of duties, controls preventing minting without corresponding funds, anomaly detection and private-key governance.
StablR has now answered one part of that problem by quantifying the unauthorised tokens still in circulation. The underlying technical questions, however, remain largely unanswered.
EFRI’s submission referred to Blockaid’s earlier analysis that compromise of a single private key in a reported 1-of-3 multisig configuration was sufficient to exercise the relevant minting authority. StablR’s new notification states that an external unauthorised third party gained access to part of its infrastructure, but it still does not publicly explain which access or key was compromised, whether the reported 1-of-3 configuration was correct, why one compromised credential could enable the creation of unbacked tokens, or what specific technical and governance changes have since been implemented.
This is particularly relevant because StablR’s own regulatory documentation states that STB Software Development B.V., a Dutch group company, owns the IT and the platform, while regulatory responsibility remains with the licensed issuer StablR Ltd. EFRI therefore also asked the MFSA to examine the allocation of ICT responsibilities and the relevant intra-group arrangements under DORA.
Redemption remains suspended
A second central issue remains unresolved. More than three months after the incident, minting and redemption remain suspended.
EFRI expressly acknowledged in its letter that a suspension of redemption may form part of a lawful recovery response under MiCAR. The question raised was therefore not whether redemption can ever be suspended, but on what legal and supervisory basis the suspension has continued for several months.
EFRI asked whether the MFSA itself had made a determination under Article 46(4) MiCAR or whether the suspension rests on StablR’s Recovery Plan under Article 46(1)(c). It also asked how the continued suspension is being assessed against the redemption right under Article 49(4) and whether the MFSA would clarify its legal basis and current status for token holders.
StablR’s 25 August notification confirms that its Recovery Plan remains activated and that redemption remains suspended. It still provides no timetable for resumption.
EFRI also asked the MFSA a separate question under Article 47 MiCAR: whether StablR is unable, or likely to be unable, to fulfil its obligations and whether the conditions for implementing an orderly Redemption Plan have therefore been assessed. EFRI further asked whether partial or pro-rata redemption from available assets could be implemented while ensuring equitable treatment of token holders.
StablR’s latest statement refers to its Recovery Plan, but provides no public information on whether the separate Article 47 assessment has taken place.
Who bears the consequences of the unauthorised tokens?
StablR’s new distinction between tokens issued through its authorised process and unauthorised tokens created during the incident also raises a fundamental question for holders.
EURR and USDR are transferable blockchain assets. StablR has not publicly explained what happens where an unauthorised token has subsequently been transferred, exchanged or acquired by a third party who may have had no knowledge of its origin.
The issue is therefore no longer merely whether unbacked tokens exist. StablR has now confirmed that they do. The most important question is what legal rights attach to such tokens once they circulate among third parties and how a holder is supposed to determine whether a particular EURR or USDR carries a redemption claim against the issuer.
There is also an unresolved transparency issue concerning StablR’s published documentation. EFRI’s 24 August submission noted that the EURR white paper continued to state that EURR would at all times be fully backed and that holders had a right to redemption at any time and at par value. EFRI therefore asked whether the backing shortfall and prolonged redemption suspension required publication of a modified white paper under Article 51(12) MiCAR.
StablR’s new disclosure makes that question more, rather than less, relevant: the issuer has now itself quantified millions of EURR and USDR currently in circulation without corresponding reserve assets at levels materially exceeding the estimates previously reported in the aftermath of the incident.
The issue is not confined to the white paper. As of 28 August 2026, StablR’s own website continues to describe EURR and USDR generally as “Fully collateralized” and “100% collateralized”. Its FAQ also states that EURR can be redeemed “at any time and at par value”. These statements now sit alongside StablR’s own confirmation that millions of unauthorised EURR and USDR remain in circulation without reserve backing and that redemption remains suspended.
At a minimum, this apparent inconsistency requires clarification for current and prospective token holders.
StablR has provided figures. The MFSA still has to provide answers.
EFRI’s 24 August submission went considerably further than asking StablR to disclose the size of the incident. It asked the MFSA to clarify the legal basis of the continuing redemption suspension, assess whether a Redemption Plan should be implemented, address the white-paper issue, review StablR’s continuing licensing conditions and reconsider relevant fitness-and-properness questions in light of both the cyber incident and the additional evidence concerning Payvision.
The 25 August notification therefore represents an important improvement in transparency, but it does not resolve the central supervisory questions.
StablR has now confirmed that millions of unauthorised and unbacked EURR and USDR remain in circulation while redemption remains suspended more than three months after the incident. StablR has provided some of the missing facts. The MFSA still needs to explain the supervisory consequences.
Who bears the consequences?
As long as more than 20 million unbacked token units remain in circulation, the potential for consumer harm remains: subsequent purchasers may acquire EURR or USDR without knowing whether StablR considers the tokens they hold to carry an enforceable redemption claim.
And the supervisory assessment should not lose sight of the history of StablR’s management. Gijs op de Weegh, StablR’s CEO and director, previously co-founded Payvision and signed merchant agreements with entities used for Gal Barak’s platforms. EFRI’s review of the criminal files documents payment relationships through which substantial volumes were processed for those platforms, whose victims suffered extensive losses across Europe. Please refer to our reports [here] and [here] for the underlying evidence.







