Incident case file
Sign in to watchEcho Protocol — Admin Key Compromise / eBTC Unauthorized Mint
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker address not disclosed; 384 ETH (~$821K-822K) routed through Tornado Cash
Timeline: On 18 May 2026, an attacker compromised Echo Protocol's administrative key on Monad (access control issue, not smart contract flaw). They minted 1,000 unbacked eBTC (~$76.7M notional). Deposit of 45 eBTC ($3.45M) on Curvance, borrowing 11.29 WBTC, bridge to Ethereum, swap to ETH. Around 22:00 UTC, Curvance detected the anomaly and paused the Echo eBTC market. dcfgod (X) publicly flagged the exploit. 384 ETH (~$821K) routed via Tornado Cash. Echo suspended all cross-chain transactions. Keone Hon (Monad co-founder) confirmed 'Monad network not affected', ~$816,000 actually extracted. On 19 May 2026, Echo confirmed the admin key compromise, regained control and burned the remaining 955 eBTC. Curvance isolated markets architecture confirmed no smart contract compromised. Recurring 2026 pattern: admin key compromise on multi-chain deployments, exploitation via isolated lending markets.
Sources and coverage
- Articlecoindesk.comhttps://www.coindesk.com/business/2026/05/19/echo-protocol-suffers-usd76-million-exploit-in-ebtc-minting-attack-on-monad
- Articletheblock.cohttps://www.theblock.co/post/401771/echo-protocol-monad-exploit
- Articlenews.bitcoin.comhttps://news.bitcoin.com/echo-protocol-pauses-monad-bridge-after-admin-key-breach-sparks-816k-loss/
- Articlecrypto.newshttps://crypto.news/echo-protocol-pauses-bridge-after-attacker-mints-76m-ebtc/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/19/echo-exploit-hacker-moves-821k-through-tornado-after-ebtc-mint/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)