Reading about Dusk building EURQ, its regulated euro, together with Quantoz this week put me right back at a summer job in a small print shop. A sign taped above the safe read "two signatures required for any withdrawal." The lock underneath only needed one key, and three copies of that key were floating around the shop. One week the till came up short, someone had opened it alone. Nothing about the paperwork was wrong. The rule existed. It just wasn't built into the lock.
Call it the paperwork peg: a promise written into policy that the mechanism underneath never actually enforces.
On May 24, that exact gap took down a regulated euro stablecoin. StablR, a Malta-licensed, MiCA-compliant issuer, ran its minting contract on a 1-of-3 multisig, meaning any single key alone could authorize new supply. One key got compromised. The attacker added themselves as an owner, removed the two legitimate signers, and minted 8.35 million USDR and 4.5 million EURR out of thin air, about $13.5 million at face value. EURR fell to $0.85, USDR crashed as low as $0.40. StablR had every MiCA box checked, reserve requirements, redemption rights, monthly proof-of-reserves. None of those boxes covered how many keys it took to mint.
EURQ sits in the same regulatory category, an Electronic Money Token issued by Quantoz under MiCA, built into Dusk as the settlement currency for Dusk Pay's regulated payment rail. Dusk's own transaction layer enforces balance integrity and ownership cryptographically on every transfer, through Moonlight or Phoenix, not through a policy document.
What I don't have visibility into yet: whether Quantoz's own minting and custody setup for EURQ, the multisig threshold, hardware security modules, time-locks, has actually been disclosed or audited against exactly the failure that hit StablR. A MiCA license didn't stop that one. The question isn't whether Dusk's chain is sound, it's whether the key management sitting above it is.
#dusk $DUSK @Dusk
Call it the paperwork peg: a promise written into policy that the mechanism underneath never actually enforces.
On May 24, that exact gap took down a regulated euro stablecoin. StablR, a Malta-licensed, MiCA-compliant issuer, ran its minting contract on a 1-of-3 multisig, meaning any single key alone could authorize new supply. One key got compromised. The attacker added themselves as an owner, removed the two legitimate signers, and minted 8.35 million USDR and 4.5 million EURR out of thin air, about $13.5 million at face value. EURR fell to $0.85, USDR crashed as low as $0.40. StablR had every MiCA box checked, reserve requirements, redemption rights, monthly proof-of-reserves. None of those boxes covered how many keys it took to mint.
EURQ sits in the same regulatory category, an Electronic Money Token issued by Quantoz under MiCA, built into Dusk as the settlement currency for Dusk Pay's regulated payment rail. Dusk's own transaction layer enforces balance integrity and ownership cryptographically on every transfer, through Moonlight or Phoenix, not through a policy document.
What I don't have visibility into yet: whether Quantoz's own minting and custody setup for EURQ, the multisig threshold, hardware security modules, time-locks, has actually been disclosed or audited against exactly the failure that hit StablR. A MiCA license didn't stop that one. The question isn't whether Dusk's chain is sound, it's whether the key management sitting above it is.
#dusk $DUSK @Dusk