Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Markets

Echo Protocol's $76 Million Mint Came Out of a Single Compromised Key — and the Actual Take Was $816,000

An attacker minted roughly 1,000 unbacked eBTC worth $76.7 million on Echo Protocol's Monad deployment by compromising a single admin key, though the realised loss was around $816,000 after the team regained control and burned the remaining tokens.

By Oliver Bradford··4 min read
Echo Protocol's $76 Million Mint Came Out of a Single Compromised Key — and the Actual Take Was $816,000

Key Points

  • An attacker minted roughly 1,000 unbacked eBTC worth $76.7 million on Echo Protocol's Monad deployment by compromising a single admin key, though the realised loss was around $816,000 after the team regained control and burned the remaining tokens.

An attacker minted roughly 1,000 unbacked eBTC on Echo Protocol's Monad deployment on May 19, briefly inflating the supply of a Bitcoin-pegged token by about $76.7 million before the team froze the contract. The real money that left the system was closer to $816,000, almost all of it laundered through Tornado Cash. The remaining 955 eBTC have been burned.

Echo Protocol confirmed in a post-incident statement that the breach "originated from a compromised admin key affecting the Monad deployment." There was no clever exploit chain, no obscure rounding error in a smart contract, no flash-loan choreography. One private key with too much authority did the entire job. The attacker used it to assign themselves DEFAULT_ADMIN_ROLE and MINTER_ROLE, revoked the original admin, and minted at will.

The attack flow tells you what the key was actually worth. The hacker took 45 of the freshly minted eBTC — about $3.45 million at notional value — and posted it as collateral on Curvance, the Monad-native money market. They drew approximately 11.29 WBTC against it, bridged the WBTC to Ethereum, swapped into 384 ETH, and routed the proceeds through Tornado Cash. That is the entire realised loss. The other 955 eBTC sat in a wallet long enough for Echo to regain admin control and burn it.

Advertisement

728×90

Echo is a Bitcoin-focused DeFi protocol that lets BTC holders bridge to Monad, the high-throughput EVM chain that opened mainnet earlier this year. eBTC is the wrapped representation. Minting 1,000 of them with one signature was supposed to be impossible — not because the math forbids it, but because no production system should ever let one key do that much. The attack is the third major DeFi failure this month rooted in concentrated admin authority rather than smart-contract bugs.

That pattern is now the headline risk in the sector. Wasabi Protocol lost $4.55 million in late April because a single wallet held the admin role across the entire system. The 1inch liquidity provider drained for $6.7 million on May 13 hit because an allowlist function had no access control at all. Now Echo. The contracts in each case were unremarkable; the operational security around them wasn't. Audits look at code. They cannot look at how a team rotates keys, who has them, and whether multisig thresholds match the value at risk.

Echo's response has been textbook for what it is — fast contract pause, cross-chain functionality halted on Monad, an upgrade to "restrict affected operations and strengthen control over sensitive functions." The team claims it regained the admin keys after the attacker started moving funds, which is what allowed it to torch the 955 eBTC still sitting in the attacker's wallet. The bridge remains paused as of writing.

The cryptographic distinction between $76 million minted and $816,000 extracted matters more than the headline number suggests. eBTC's peg can only survive if the market believes every token is backed one-for-one by Bitcoin held in custody. The moment 1,000 unbacked units exist, the peg becomes a question of how fast the protocol can claw them back versus how fast the attacker can sell them. Echo won that race because the attacker bottlenecked themselves on Curvance — Monad's DeFi liquidity is thin enough that swapping 1,000 eBTC into anything liquid would have crashed the price before the bridge could move it.

That's a feature of the still-narrow market the attacker exploited, not a feature of the protocol. On Ethereum, with deeper pools and more bridges, the same key compromise would have resulted in a substantially larger loss. Monad is young enough that the routes out are not yet built. Future attackers using the same vector on more mature deployments will not have that problem.

The implication for Monad itself is the more uncomfortable one. The chain has positioned itself as the EVM-compatible high-throughput layer, and Echo was one of its flagship Bitcoin DeFi integrations. Total value locked across the chain is in the low billions; an incident at this scale dents the trust required to attract the next wave of deposits. Echo says it will publish a full post-mortem. The question Monad's other protocols should be asking is whether their own admin key setups would survive the same audit.

According to onchain analyst PeckShield, who first flagged the mint, this is now the 14th separate DeFi exploit recorded in May 2026. The cumulative loss across those incidents has not yet been published, but TRM Labs reported in late April that North Korea alone accounted for 76 per cent of stolen crypto value for the year through two attacks — a figure that will need updating now. Echo Protocol has said it will reimburse users affected by the realised loss, though it has not yet specified the mechanism or timeline. The compromised key is the only thing that has been confirmed; everything else, including how the attacker obtained it, remains under investigation.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Drift's Recovery Pool Pays About a Cent on Every Dollar Lost
Markets

The Drift Foundation issued one DFX token for each verified dollar taken in April's exploit, and the pool behind those 299.5 million tokens holds about $3.11 million. Tether and other partners have pledged up to $147.5 million more, none of which has arrived.

·MiningPool Staff
NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Aave Opened a USDC Market Backed by Seven Coinbase Stock Tokens
Markets

The Equities Hub on Base takes tokenized Apple, Microsoft, Nvidia and four other stocks as collateral at 65 to 79 percent, capped at about $29 million, and lends only USDC against them. The market runs continuously while the Chainlink feed pricing that collateral stops publishing from Friday evening until Sunday evening Eastern.

·MiningPool Staff
Bitget Says Its Own Approval Process Released $351.6 Million
Tech

The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.

·MiningPool Staff
Only Agave Can Run Alpenglow as Solana Starts the Testnet Phase
Tech

Anza is targeting about 150 milliseconds to finality, down from the roughly 12.8 seconds it attributes to TowerBFT, but Firedancer and Frankendancer cannot run the code yet. No mainnet date has been announced, and September 28 is a feature-gate processing date rather than a confirmed Alpenglow launch.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.