Echo Protocol is investigating a security incident involving its bridge on Monad after crypto on-chain analysts said an attacker minted 1,000 eBTC and used partEcho Protocol is investigating a security incident involving its bridge on Monad after crypto on-chain analysts said an attacker minted 1,000 eBTC and used part

Crypto Hack Hits Echo As Monad’s eBTC Market Faces Fallout

2026/05/19 17:30
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Echo Protocol is investigating a security incident involving its bridge on Monad after crypto on-chain analysts said an attacker minted 1,000 eBTC and used part of the position to extract WBTC liquidity through Curvance.

The first public alarm came from on-chain analyst DCF GOD, who wrote that Echo “may be hacked on Monad.” He added: “Someone minted 1k ebtc out of nowhere, max borrowed wbtc against it on Curvance, bridged, and tornado away.” A follow-up post pointed to a Monad transaction showing a 1,000 eBTC transfer on May 18 at 21:21:32 UTC.

$76M Crypto Mint Sparks Alarm

Lookonchain later mapped the reported sequence in more detail. According to the account, the attacker minted 1,000 eBTC, valued at about $76.64 million, deposited 45 eBTC worth roughly $3.45 million into Curvance, borrowed 11.3 WBTC worth about $867,000, bridged the WBTC to Ethereum, swapped it for 385 ETH worth about $821,000, and deposited the ETH into Tornado Cash. Lookonchain said the attacker still held 955 eBTC, valued at about $73.2 million.

Phylax Systems founder and CEO Odysseas Lamtzidis said the transaction trail pointed away from a Curvance lending flaw and toward a role-management compromise on the eBTC side. “Monad eBTC/Curvance trace: not a Curvance lending bug,” he wrote. “The eBTC admin granted DEFAULT_ADMIN_ROLE to 0x6A0109, who revoked admin, self-granted MINTER_ROLE, minted 1,000 eBTC, posted 45 eBTC as collateral, and borrowed ~11.296 WBTC.” Lamtzidis said the pattern “looks like admin-key/role compromise,” citing key transactions for the admin grant, mint and borrow.

Echo confirmed the incident without publishing a root-cause analysis. “We are currently investigating a security incident impacting the Echo bridge on Monad. All cross-chain transactions remain suspended while the investigation is underway. We will continue to provide timely updates through our official channels as more information becomes available.” The suspension makes the bridge the immediate operational focus, not simply the lending market that processed the collateral.

Curvance’s exposure appears to have come through the affected Echo eBTC market. Curvance paused that market while the teams investigated, and cited Curvance as saying there was no indication its smart contracts had been compromised and that its isolated-market architecture meant other markets were not affected. Also, Monad’s network itself was not affected.

Monad CEO Keone Hon wrote via X: “To clarify, the Monad network is not affected and is operating normally. Security researchers in their review have determined that ~$816,000 appears to have been stolen as a result of this exploit of Echo Protocol’s eBTC.

The incident illustrates a familiar bridge-to-lending failure pattern. Once a bridged or synthetic asset is treated as valid collateral, even a partial conversion path can turn a supply-side failure into real liquidity loss. In this case, the eBTC mint was used to borrow WBTC, move it off Monad, convert it into ETH, and route the funds through a mixer before the broader notional position was fully monetized.

Echo’s next update will need to answer several market-facing questions: whether the unauthorized eBTC has been neutralized, whether Curvance faces bad debt from the WBTC borrow, which bridge permissions or contracts were involved, and when cross-chain transactions can safely resume. Until then, the eBTC market on Monad remains the key pressure point for users trying to assess whether the incident was contained or merely slowed.

The Echo exploit also lands during a rough stretch for crypto infrastructure. On May 15, THORChain has lost more than $10 million across Bitcoin, Ethereum, BNB Chain and Base, including 36.75 BTC and roughly $7 million in other assets. Days later, the Verus-Ethereum Bridge was drained for about $11.5 million, with reports saying the attacker took 103.6 tBTC, 1,625 ETH and 147,000 USDC before consolidating the haul into roughly 5,402 ETH. Echo now gives markets another reminder that bridge design, collateral acceptance and liquidity routing remain one of DeFi’s most exposed attack surfaces.

[UPDATE from X:] Echo Protocol confirmed: “Earlier today, Echo Protocol identified unauthorized activity involving eBTC on Monad that resulted in unauthorized minting and associated fund loss. Our investigation indicates the issue originated from a compromised admin key affecting the Monad deployment. Based on current findings, approximately $816K was impacted on Monad. The Monad network itself was not impacted and continues to operate normally.

Since detecting the incident, we have been actively investigating potential cross-chain exposure, coordinating with ecosystem partners, and implementing additional precautionary measures. We have successfully regained control of our admin keys and burnt the remaining 955 eBTC that was in the attacker’s possession.”

At press time, the total crypto market cap stood at $2.54 trillion.

Total crypto market cap chart
시장 기회
Echo 로고
Echo 가격(ECHO)
$0.004904
$0.004904$0.004904
-10.83%
USD
Echo (ECHO) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!