Refreshed 3h ago· updates every 6h

Echo Protocol (Monad) (2026) — Crypto Hack

Not Recovered
May 18, 2026·
MonadEthereum
Amount Stolen
$816K
~$816K realized from 1,000 eBTC minted ($76.64M nominal); 384-385 ETH after bridging
Recovered
$0

Admin key compromise of Echo Protocol's eBTC contract on Monad allowed minting of 1,000 eBTC ($76.6M), but shallow liquidity limited realized losses to $816K, laundered through Tornado Cash.

Summary

Admin key compromise of Echo Protocol's eBTC contract on Monad allowed minting of 1,000 eBTC ($76.6M), but shallow liquidity limited realized losses to $816K, laundered through Tornado Cash.

How It Was Compromised — Admin Key Compromise via Attacker compromised the single admin private key of the eBTC contract (no multisig protection, no timelock, no mint cap). Gained DEFAULT_ADMIN_ROLE, revoked original admin, granted themselves MINTER_ROLE, minted 1,000 eBTC ($76.64M). Deposited 45 eBTC as collateral on Curvance protocol, borrowed 11.3 WBTC (~$868K), bridged to Ethereum, swapped to 384-385 ETH, then routed through Tornado Cash. Only ~$816K realized due to shallow Monad liquidity. Remaining 955 eBTC later burned by team after regaining admin control. Monad blockchain itself was unaffected.

Admin Key CompromiseAttacker compromised the single admin private key of the eBTC contract (no multisig protection, no timelock, no mint cap). Gained DEFAULT_ADMIN_ROLE, revoked original admin, granted themselves MINTER_ROLE, minted 1,000 eBTC ($76.64M). Deposited 45 eBTC as collateral on Curvance protocol, borrowed 11.3 WBTC (~$868K), bridged to Ethereum, swapped to 384-385 ETH, then routed through Tornado Cash. Only ~$816K realized due to shallow Monad liquidity. Remaining 955 eBTC later burned by team after regaining admin control. Monad blockchain itself was unaffected.

On May 18-19 2026, Echo Protocol on the Monad blockchain suffered an admin key compromise of its eBTC (Elastic Bitcoin) contract. The attacker gained the DEFAULT_ADMIN_ROLE, revoked the original admin's access, and granted themselves the MINTER_ROLE — enabled by the contract's single-admin design with no multisig protection, no timelock, and no mint cap. They minted 1,000 eBTC nominally worth $76.64M. However, due to the shallow liquidity on the nascent Monad ecosystem, the attacker could only realize approximately $816K in value. They deposited 45 eBTC as collateral on Curvance, borrowed 11.3 WBTC (~$868K), bridged the WBTC to Ethereum, swapped to 384-385 ETH, and routed through Tornado Cash. Monad CEO Keone Hon confirmed the realized loss at approximately $816K and clarified that the Monad blockchain itself was unaffected. Echo Protocol subsequently suspended cross-chain activity, and the team regained admin key control, burning the remaining 955 eBTC.

Fund Flow & Laundering Analysis

The $816K realized from the exploit was laundered through a multi-step process: 45 eBTC deposited as collateral on Curvance protocol -> 11.3 WBTC (~$868K) borrowed -> bridged to Ethereum -> swapped to 384-385 ETH -> routed through Tornado Cash for privacy obfuscation. The attacker's choice to use Curvance for borrowing rather than direct DEX swaps suggests awareness of on-chain slippage monitoring. The Tornado Cash routing makes recovery of the laundered $816K highly unlikely.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.