Posts  / #POST-243779
REDDIT

a MiCA-licensed, fully authorized stablecoin issuer just got hacked through the exact thing licensing was supposed to prevent

H
Jul 22, 2026 · 11:45

Proof that the regulated perimeter does not equal the secure perimeter. been seeing a lot of "just wait until everything's regulated, then it'll be safe" takes in defi/stablecoin threads lately, so this felt worth sharing.

hacken released its q2 security and compliance report, and in this era of regulation boom, this case is worth sharing.

so, stablr (usdr/eurr) is mica-authorized lost $2.8M this quarter because one of its three mint keys got compromised

what makes this specific case interesting is that key/mint-authority management is exactly the kind of operational control mica's underlying framework (dora) is supposed to require issuers to have locked down. it's not a gap in the rules on paper. it's that authorization checks whether you have a security policy document and pass a point-in-time pentest, not whether your actual key management setup survives a real attempt. the loss happened inside the regulated perimeter, after full authorization, not from some unlicensed fly-by-night issuer.

not saying mica is pointless, but "licensed" not always mean "operationally secure"