Echo Protocol, a Bitcoin liquidity layer running on the Monad blockchain, was hit by a $76.7 million exploit late on May 18, after an attacker minted 1,000 unbacked eBTC tokens, deposited a fraction of them into the Curvance money market, and routed roughly $821,700 in stolen value through Tornado Cash. Investigators say the breach was not a smart contract bug but an admin private key compromise, exposing how a single mismanaged signer can puncture a multi-million dollar synthetic asset.
The minted tokens were eBTC, a synthetic Bitcoin issued by Echo and used as collateral across Monad-based DeFi protocols. A synthetic asset is a token engineered to track the price of another asset, in this case bitcoin, without holding the underlying coin in a one-to-one custodial reserve.
Key takeaways
- An attacker minted 1,000 eBTC, nominally worth about $76.7 million, on Echo Protocol’s Monad deployment on May 18, 2026.
- Confirmed extracted value sits near $821,700 in ETH routed to Tornado Cash; wallets tied to the attack still hold roughly 955 eBTC valued above $73 million on paper.
- Root cause was an admin private key compromise with no timelock, no minting cap, and no rate limit, according to early post-mortem analysis.
- Echo halted all cross-chain transactions, Curvance paused the affected lending market, and Monad CEO Keone Hon said the chain’s consensus was not touched.
Published: May 19, 2026 09:10 UTC
How the attack unfolded
Curvance, a cross-chain lending venue, flagged an anomaly in its Echo eBTC market at roughly 6:00 PM EST on May 18, according to a post-incident timeline from BeInCrypto. By that point, the attacker had already issued 1,000 freshly minted eBTC tokens to a single address.
The exploiter then deposited 45 eBTC, worth about $3.45 million at the time, into Curvance as collateral. That collateral was used to borrow approximately 11.29 wrapped bitcoin (WBTC), which the attacker bridged to Ethereum, swapped for ether, and sent in tranches totaling 384 ETH (around $821,700) to the Tornado Cash mixer.
The remaining 955 eBTC sit in wallets tied to the attack and have not moved. Because those tokens are not backed by any custodied bitcoin, their on-chain market value will collapse if Echo’s holders try to redeem them, which is why post-mortem estimates put the realized loss in the low seven figures rather than near the headline $76 million.
Admin keys, not code, were the failure point
Independent developer “Marioo” published an early breakdown calling the incident operational rather than technical. The eBTC contract behaved exactly as written. The problem was who had permission to call it.
Marioo’s review pointed to four specific gaps: a single signature controlling the admin role, no timelock on privileged actions, no maximum supply cap or minting rate limit on the eBTC token, and no independent supply sanity check inside Curvance to halt deposits when the eBTC total drifted from expected backing.
Cointelegraph corroborated the admin key compromise theory, citing on-chain analysts who traced the minting transactions back to a wallet holding upgrade and mint permissions on the Echo bridge contract.
Why this matters for Monad and synthetic Bitcoin
Monad is one of the most-watched new layer-1 blockchains, marketed as a high-throughput, EVM-compatible alternative to Ethereum. Echo is among the larger DeFi protocols built on top of it, and eBTC was meant to be Monad’s flagship synthetic bitcoin for use across lending, perps, and AMMs.
Monad CEO Keone Hon publicly distanced the network from the exploit, saying Monad’s consensus and base layer were untouched and that the failure was contained to an application built on the chain. That framing matters because new L1s are routinely judged on the security of the DeFi apps built on top of them rather than the chain itself.
For users, the practical effect is that any open eBTC positions across Monad DeFi are now suspect until Echo publishes a recovery plan. Curvance has paused the affected market. Other protocols that accept eBTC as collateral are likely to follow.
May’s exploit count climbs to 14
The Echo incident is the 14th confirmed DeFi or bridge exploit reported in May 2026, per BeInCrypto’s running tally. The list includes the THORChain cross-chain halt on May 15, the Verus Protocol Ethereum bridge drain, and earlier hits on Transit Finance, TrustedVolumes, and Ekubo.
Admin key compromises and bridge logic failures, not smart contract bugs in token code, account for most of the dollar losses across that group, a pattern security firms have flagged since the $292 million KelpDAO exploit in April.
What comes next
Echo Protocol said cross-chain transactions will remain suspended until its review concludes. A public post-mortem is expected within days. Curvance has not committed to reopening the eBTC market.
Watch for three things in the coming hours: whether the attacker tries to move the remaining 955 eBTC before holders can react, whether Echo proposes a token reissuance or socialized loss, and whether other Monad protocols freeze eBTC support to contain contagion.
Frequently asked questions
What is eBTC?
eBTC is a synthetic bitcoin token issued by Echo Protocol on Monad. It is designed to trade at parity with bitcoin and is used as collateral in Monad-based lending, trading, and liquidity protocols. Unlike WBTC, eBTC’s backing model relies on Echo’s smart contracts and bridge rather than a single regulated custodian.
How much was actually stolen in the Echo exploit?
The nominal mint was 1,000 eBTC, worth about $76.7 million on paper. Confirmed extracted value is roughly $821,700, which the attacker bridged out as ether and sent to Tornado Cash. The remaining 955 eBTC sit in attacker-linked wallets and would crash in value if dumped, since they are unbacked.
Was Monad itself hacked?
No. Monad CEO Keone Hon said the chain’s consensus and base layer were not affected. The exploit was contained to Echo Protocol’s bridge and admin permissions. The incident is a protocol-level failure on Monad, not a failure of Monad.








