Echo Protocol Breach Minted 1,000 Unbacked eBTC, Spilling Risk Across Monad Apps

Echo Protocol Breach Minted 1,000 Unbacked eBTC, Spilling Risk Across Monad Apps

N
News Editor 01
2026-07-22 13:50:14
An admin key compromise at Echo Protocol let an attacker mint 1,000 unbacked eBTC and borrow 11.3 Wrapped Bitcoin through Curvance. The team later burned the remaining 955 eBTC and halted cross-chain activity.
Echo ProtocolMonadDeFi securityeBTCCurvance

Echo Protocol suffered a major security breach on Monad after an attacker compromised a single admin private key and minted 1,000 unbacked eBTC. At face value, the newly created tokens were worth about $76.6 million at the time of the incident. The failure was not tied to a smart contract coding bug. It came from broken operational security and excessive authority attached to one key.

The attacker gained admin and minting control

After getting access, the attacker changed system settings and granted themselves both administrative and mining privileges. That opened the door to mint the unsupported eBTC from a zero address while paying almost nothing in gas. To turn fake collateral into recoverable value, the attacker deposited 45 eBTC into Curvance, a separate lending protocol, and borrowed 11.3 Wrapped Bitcoin against it. Using the token price cited in the source, $76.5K per Wrapped Bitcoin, the extracted value came to roughly $820K to $867K.

Funds moved to Ethereum and about 385 ETH hit Tornado Cash

The borrowed assets were then moved off Monad. The attacker bridged the funds to Ethereum and swapped them into native ETH. From there, around 385 ETH was routed through Tornado Cash, making the trail much harder to follow. Even after that laundering step, the attacker still held 955 eBTC in a personal wallet. On paper, that balance was worth more than $73 million, but it did not turn into equivalent realized proceeds.

Echo froze bridges while Curvance paused the eBTC market

Echo Protocol responded by suspending all cross-chain bridge transactions to contain the breach. Curvance also halted its eBTC market to shield remaining liquidity providers. Within hours, the team burned the remaining 955 eBTC. Because market liquidity for eBTC was limited, the attacker could not dump the rest of the supply, which kept the realized loss tied to the amount first borrowed from Curvance rather than the full notional value of the mint.

For regular users, the source says there was no direct wallet drain. The damage landed elsewhere. Lenders and liquidity providers on Curvance were left facing bad debt, showing how a failure in one application can pass losses into another protocol connected to the same ecosystem.

The breach was at the app layer, not the Monad base network

The incident also triggered questions about Monad itself. Based on the source material, this was an application-level operational failure, not a weakness in the underlying blockchain. Monad remained functional for normal transactions. Still, the $76 million eBTC episode exposed how fragile newer DeFi deployments can be when role management, admin key security, and hard caps on fresh collateral are not strict enough.

The case points back to a familiar problem in DeFi: key theft can be just as damaging as a code exploit. Here, the attacker did not need a complex bug. Control of one powerful private key was enough to mint assets and draw value from a separate lending market.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.