Echo Protocol exploit on Monad allows attacker to mint 1K eBTC and max-borrow WBTC on Curvance.
Security & Exploits ·
Echo Protocol experienced a suspected exploit on Monad after an attacker minted 1,000 eBTC without backing on May 18, 2026. The newly created tokens, valued at roughly $77 million at Bitcoin's spot price of approximately $77,000, were used to secure a loan of real WBTC on the Curvance lending platform. The attacker then bridged the borrowed WBTC and moved funds through Tornado, while the remaining 99% of the counterfeit supply sits in the attacker's wallet, constrained by liquidity limitations on Monad.
Security researchers analyzing the incident determined the attack stemmed from a compromised admin private key rather than a smart contract vulnerability. The attacker granted itself admin and minter privileges on Echo Protocol's eBTC token contract, revoked the original administrator's access, and minted the 1,000 eBTC in a single transaction costing $0.0003 in gas. The attacker then deposited the fake eBTC as collateral on Curvance to borrow real WBTC.
Monad co-founder Keone acknowledged the incident and stated the team and external security researchers were investigating. As of the report's writing, Echo Protocol and Curvance have not published statements on the compromise.