Cryptopolitan
2026-05-19 08:38:35

Echo Protocol exploit sparks alarm after $73M eBTC mint

The Bitcoin DeFi project Echo fell victim to an exploit on Monday. Blockchain security platform Lookonchain shows a hacker minted 1,000 eBTC ($76.64M) on Monad, and then collateralized 45 eBTC on Curvance to borrow 11.29 WBTC worth $867,700. The attacker later redirected the assets to Ethereum and converted them to native ETH while funneling 384 ETH into Tornado Cash. The attacker’s wallet still retains 955 eBTC of the fake supply, which the platform estimates is worth about $73.2 million. Blockchain firm OnChain Lens even confirmed: “The attacker still appears to control a significant amount of minted eBTC.” The incident comes as the DeFi sector continues to grapple with a rising wave of protocol breaches and private key compromises. Curvance says the exploit only affected Monad’s eBTC/WBTC market Monad and Curvance have both now publicly recognized the exploit. Monad Co-founder Keone Hon posted on X: We’re aware of an incident related to Echo Protocol’s eBTC on Monad, and security researchers are investigating. Keone Hon In another post, the founder noted they had lost about $816,000 to the exploit. Curvance also shared , “Out of an abundance of caution, the affected market has been paused while our team actively investigates the situation alongside ecosystem partners.” It also asserted that the attack was contained to Monad’s eBTC/WBTC market. Other Curvance pools and major cross-chain platforms, including Aave, Morpho, Spark, and Fluid, were untouched. Although it isn’t known exactly how the attacker managed to mint eBTC, experts suggested it could be due to a private key compromise, a deployment error, or a smart contract flaw. The attacker opted against a 1,000 eBTC DEX market dump to avoid the severe slippage caused by Monad’s shallow liquidity pool. Instead, they executed a lending-based extraction method, replicating the strategy used to siphon funds from Resolv and KelpDAO before. Have hackers been targeting more DeFi platforms? According to DeFiLlama, the DeFi space had already suffered 13 hacks this month before the Echo Protocol exploit. The Echo Protocol is also the third major decentralized finance platform to fall victim to an exploit in the last five days. As earlier reported by Cryptopolitan, THORChain was compromised on May 15, and hackers pocketed more than $10 million. THORChain suspended trading after the incident, reassuring users that only protocol-owned funds were affected. It acknowledged it “automatically detected abnormal behavior and halted signing activity,” which prevented more outbound transactions. Speaking on the attack, on-chain investigator ZachXBT said the exploiter targeted the platform across Bitcoin, Ethereum, BNB Chain, and Base. A subsequent exploit hit the Verus-Ethereum Bridge three days later, resulting in the loss of $11.58 million in digital assets. Security researchers at Blockaid traced the exploit to the wallet address “0x5aBb…D5777.” Blockchain security firm Peckshield also detailed that the exploiter made off with 103.6 tBTC, 1,625 ETH, and 147,000 USDC, later converting the assets into about 5,402 ETH. Another security firm reporting the attack, GoPlus, noted, “It is highly likely to be cross-chain message validation/signature forgery, withdrawal logic bypass, or access control flaw.” Meanwhile, the Verus team contended that it’s still investigating the incident. DeFi platforms have become a prime target for attackers in the last few years. DeFiLlama estimates that uninsured lending protocols have suffered $7.7 billion in exploit-related losses over the past 6 years. More than $600 million was lost to hacks this April, with Drift and KelpDAO taking major hits. More recently, Nexus Mutual’s Founder, Hugh Karp, even highlighted that many of the latest hacks were caused by operational failures, pointing to a mismatch between risk and insurance coverage. Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free .

가장 많이 읽은 뉴스

관련뉴스

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.