Echo Protocol, a DeFi lending protocol built on Monad, suffered a major security breach. An attacker obtained the protocol’s admin private key and directly called the mint function to generate 1,000 eBTC (a BTC-pegged token worth approximately $76.7 million). After a multi-step cross-chain laundering process, roughly 384 ETH ($820,000) was sent to the crypto mixer Tornado Cash.
Attack Breakdown: Minting, Collateralizing, Bridging, and Laundering
According to on-chain data from PeckShieldAlert, the attacker didn't simply steal existing assets — they exploited the admin key to mint new eBTC out of thin air. The attack followed a pre-tested sequence: first, 45 eBTC (~$3.45 million) was deposited into Curvance as collateral; then approximately 11.29 WBTC ($868,000) was borrowed; the WBTC was bridged to Ethereum mainnet and swapped for ETH; finally, 384 ETH was funneled into Tornado Cash.
What stands out is that the attacker had run a dry run hours before the real attack. On-chain data shows a tiny test transaction following the exact same steps, indicating the attacker rehearsed the entire money laundering pathway before going live. Such rehearsed attacks are rarely documented in public, suggesting a high level of premeditation.
Yuxian: Admin Single-Point Private Key Failure, Not a Code Bug
Yuxian, founder of SlowMist, posted on X: "Yet another case of a stupid single-point admin private key compromise." He stressed that the root cause was not a vulnerability in the smart contract code, but a centralized admin privilege controlled by a single private key. Once exposed, the attacker gained unlimited minting authority, rendering the entire collateral and liquidation mechanism useless.
This type of “Admin Key attack” is all too common in DeFi. Many projects prioritize operational convenience over security, failing to implement multisig or timelock mechanisms, leaving a single point of failure. Yuxian’s blunt words highlight a persistent blind spot in DeFi’s rush to scale.
At press time, Echo Protocol had not released an official statement. The front-end interface appeared to be paused, preventing users from withdrawing or borrowing. The scope of affected funds and any potential compensation plan remain unclear.

