Echo Protocol Hacked: Admin Private Key Compromised, Attacker Mints 1,000 eBTC and Launders 384 ETH

Echo Protocol Hacked: Admin Private Key Compromised, Attacker Mints 1,000 eBTC and Launders 384 ETH

N
News Editor 01
2026-07-23 19:30:15
Monad-based DeFi protocol Echo Protocol was hacked after an attacker gained access to the admin private key, minting 1,000 eBTC (~$76.7M). Through a series of cross-chain moves, 384 ETH (~$820K) ended up in Tornado Cash. SlowMist founder Yuxian attributed the breach to a single-point private key compromise, not a smart contract bug.
Echo ProtocolSecurity BreachPrivate Key LeakHacker AttackDeFi

Echo Protocol, a DeFi lending protocol built on Monad, suffered a major security breach. An attacker obtained the protocol’s admin private key and directly called the mint function to generate 1,000 eBTC (a BTC-pegged token worth approximately $76.7 million). After a multi-step cross-chain laundering process, roughly 384 ETH ($820,000) was sent to the crypto mixer Tornado Cash.

Attack Breakdown: Minting, Collateralizing, Bridging, and Laundering

According to on-chain data from PeckShieldAlert, the attacker didn't simply steal existing assets — they exploited the admin key to mint new eBTC out of thin air. The attack followed a pre-tested sequence: first, 45 eBTC (~$3.45 million) was deposited into Curvance as collateral; then approximately 11.29 WBTC ($868,000) was borrowed; the WBTC was bridged to Ethereum mainnet and swapped for ETH; finally, 384 ETH was funneled into Tornado Cash.

What stands out is that the attacker had run a dry run hours before the real attack. On-chain data shows a tiny test transaction following the exact same steps, indicating the attacker rehearsed the entire money laundering pathway before going live. Such rehearsed attacks are rarely documented in public, suggesting a high level of premeditation.

Yuxian: Admin Single-Point Private Key Failure, Not a Code Bug

Yuxian, founder of SlowMist, posted on X: "Yet another case of a stupid single-point admin private key compromise." He stressed that the root cause was not a vulnerability in the smart contract code, but a centralized admin privilege controlled by a single private key. Once exposed, the attacker gained unlimited minting authority, rendering the entire collateral and liquidation mechanism useless.

This type of “Admin Key attack” is all too common in DeFi. Many projects prioritize operational convenience over security, failing to implement multisig or timelock mechanisms, leaving a single point of failure. Yuxian’s blunt words highlight a persistent blind spot in DeFi’s rush to scale.

At press time, Echo Protocol had not released an official statement. The front-end interface appeared to be paused, preventing users from withdrawing or borrowing. The scope of affected funds and any potential compensation plan remain unclear.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.