Attacker exploited eBTC admin role on Monad to mint $77M in fake wrapped Bitcoin and steal $870K of real WBTC from Curvance lending protocol.
Security & Exploits ·
An attacker exploited administrative controls on Echo Protocol's eBTC token to mint 1,000 fake wrapped Bitcoin on Monad, worth roughly $77M at current spot prices. The attacker then deposited a portion as collateral on the Curvance lending protocol and extracted approximately $870K in real WBTC; the remaining 99% of the unbacked supply remains parked in the attacker's wallet because Monad's lending and DEX liquidity cannot absorb it.
The attack exploited a familiar failure mode: the attacker granted themselves the DEFAULT_ADMIN_ROLE on the eBTC contract, used that to self-assign MINTER_ROLE, and then revoked admin access to obscure the trail. This privileged-role vulnerability mirrors exploits on Resolv in March and KelpDAO in April, though the realized loss here is roughly 30 times smaller than Resolv and over 250 times smaller than KelpDAO. The pattern reflects a structural weakness across nascent deployments on younger blockchains that lack the operational safeguards—multisig keys, timelocks, paranoid role separation—accumulated on more mature chains like Ethereum.
Final damage assessments, the extent of the attacker's holdings, and any recovery plan remain uncertain. Echo Protocol and Curvance had not issued public statements as of the initial reporting on May 18, 2026, and on-chain figures may shift as post-mortems emerge from the affected teams and external security researchers investigating the incident.