Echo Protocol suffered a major security breach on Monad after an attacker compromised a single admin private key and minted 1,000 unbacked eBTC. At face value, the newly created tokens were worth about $76.6 million at the time of the incident. The failure was not tied to a smart contract coding bug. It came from broken operational security and excessive authority attached to one key.
The attacker gained admin and minting control
After getting access, the attacker changed system settings and granted themselves both administrative and mining privileges. That opened the door to mint the unsupported eBTC from a zero address while paying almost nothing in gas. To turn fake collateral into recoverable value, the attacker deposited 45 eBTC into Curvance, a separate lending protocol, and borrowed 11.3 Wrapped Bitcoin against it. Using the token price cited in the source, $76.5K per Wrapped Bitcoin, the extracted value came to roughly $820K to $867K.
Funds moved to Ethereum and about 385 ETH hit Tornado Cash
The borrowed assets were then moved off Monad. The attacker bridged the funds to Ethereum and swapped them into native ETH. From there, around 385 ETH was routed through Tornado Cash, making the trail much harder to follow. Even after that laundering step, the attacker still held 955 eBTC in a personal wallet. On paper, that balance was worth more than $73 million, but it did not turn into equivalent realized proceeds.
Echo froze bridges while Curvance paused the eBTC market
Echo Protocol responded by suspending all cross-chain bridge transactions to contain the breach. Curvance also halted its eBTC market to shield remaining liquidity providers. Within hours, the team burned the remaining 955 eBTC. Because market liquidity for eBTC was limited, the attacker could not dump the rest of the supply, which kept the realized loss tied to the amount first borrowed from Curvance rather than the full notional value of the mint.
For regular users, the source says there was no direct wallet drain. The damage landed elsewhere. Lenders and liquidity providers on Curvance were left facing bad debt, showing how a failure in one application can pass losses into another protocol connected to the same ecosystem.
The breach was at the app layer, not the Monad base network
The incident also triggered questions about Monad itself. Based on the source material, this was an application-level operational failure, not a weakness in the underlying blockchain. Monad remained functional for normal transactions. Still, the $76 million eBTC episode exposed how fragile newer DeFi deployments can be when role management, admin key security, and hard caps on fresh collateral are not strict enough.
The case points back to a familiar problem in DeFi: key theft can be just as damaging as a code exploit. Here, the attacker did not need a complex bug. Control of one powerful private key was enough to mint assets and draw value from a separate lending market.

