The Bitcoin DeFi project Echo fell victim to an exploit. The hacker minted 1k eBTC on Monad, and then collateralized 45 eBTC on Curvance to borrow 11.29 WBTC.The Bitcoin DeFi project Echo fell victim to an exploit. The hacker minted 1k eBTC on Monad, and then collateralized 45 eBTC on Curvance to borrow 11.29 WBTC.

Echo Protocol exploit sparks alarm after $73M eBTC mint

2026/05/19 16:38
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

The Bitcoin DeFi project Echo fell victim to an exploit on Monday. Blockchain security platform Lookonchain shows a hacker minted 1,000 eBTC ($76.64M) on Monad, and then collateralized 45 eBTC on Curvance to borrow 11.29 WBTC worth $867,700. The attacker later redirected the assets to Ethereum and converted them to native ETH while funneling 384 ETH into Tornado Cash.

The attacker’s wallet still retains 955 eBTC of the fake supply, which the platform estimates is worth about $73.2 million. Blockchain firm OnChain Lens even confirmed: “The attacker still appears to control a significant amount of minted eBTC.”

Echo Protocol exploit sparks alarm after $73M eBTC mint

The incident comes as the DeFi sector continues to grapple with a rising wave of protocol breaches and private key compromises.

Curvance says the exploit only affected Monad’s eBTC/WBTC market

Monad and Curvance have both now publicly recognized the exploit. Monad Co-founder Keone Hon posted on X:

In another post, the founder noted they had lost about $816,000 to the exploit. Curvance also shared, “Out of an abundance of caution, the affected market has been paused while our team actively investigates the situation alongside ecosystem partners.”

It also asserted that the attack was contained to Monad’s eBTC/WBTC market. Other Curvance pools and major cross-chain platforms, including Aave, Morpho, Spark, and Fluid, were untouched. Although it isn’t known exactly how the attacker managed to mint eBTC, experts suggested it could be due to a private key compromise, a deployment error, or a smart contract flaw.

The attacker opted against a 1,000 eBTC DEX market dump to avoid the severe slippage caused by Monad’s shallow liquidity pool. Instead, they executed a lending-based extraction method, replicating the strategy used to siphon funds from Resolv and KelpDAO before.

Have hackers been targeting more DeFi platforms?

According to DeFiLlama, the DeFi space had already suffered 13 hacks this month before the Echo Protocol exploit. The Echo Protocol is also the third major decentralized finance platform to fall victim to an exploit in the last five days.

As earlier reported by Cryptopolitan, THORChain was compromised on May 15, and hackers pocketed more than $10 million. THORChain suspended trading after the incident, reassuring users that only protocol-owned funds were affected. It acknowledged it “automatically detected abnormal behavior and halted signing activity,” which prevented more outbound transactions.

Speaking on the attack, on-chain investigator ZachXBT said the exploiter targeted the platform across Bitcoin, Ethereum, BNB Chain, and Base.

A subsequent exploit hit the Verus-Ethereum Bridge three days later, resulting in the loss of $11.58 million in digital assets. Security researchers at Blockaid traced the exploit to the wallet address “0x5aBb…D5777.” Blockchain security firm Peckshield also detailed that the exploiter made off with 103.6 tBTC, 1,625 ETH, and 147,000 USDC, later converting the assets into about 5,402 ETH.

Another security firm reporting the attack, GoPlus, noted, “It is highly likely to be cross-chain message validation/signature forgery, withdrawal logic bypass, or access control flaw.” Meanwhile, the Verus team contended that it’s still investigating the incident.

DeFi platforms have become a prime target for attackers in the last few years. DeFiLlama estimates that uninsured lending protocols have suffered $7.7 billion in exploit-related losses over the past 6 years. More than $600 million was lost to hacks this April, with Drift and KelpDAO taking major hits.

More recently, Nexus Mutual’s Founder, Hugh Karp, even highlighted that many of the latest hacks were caused by operational failures, pointing to a mismatch between risk and insurance coverage.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Market Opportunity
Echo Logo
Echo Price(ECHO)
$0.005191
$0.005191$0.005191
-3.51%
USD
Echo (ECHO) Live Price Chart

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Euro wavers amid mixed Eurozone data, rising geopolitical tensions

Euro wavers amid mixed Eurozone data, rising geopolitical tensions

The post Euro wavers amid mixed Eurozone data, rising geopolitical tensions appeared on BitcoinEthereumNews.com. The Euro (EUR) holds marginal losses against the
Share
BitcoinEthereumNews2026/06/01 18:41
FCA, crackdown on crypto

FCA, crackdown on crypto

The post FCA, crackdown on crypto appeared on BitcoinEthereumNews.com. The regulation of cryptocurrencies in the United Kingdom enters a decisive phase. The Financial Conduct Authority (FCA) has initiated a consultation to set minimum standards on transparency, consumer protection, and digital custody, in order to strengthen market confidence and ensure safer operations for exchanges, wallets, and crypto service providers. The consultation was published on May 2, 2025, and opened a public discussion on operational responsibilities and safeguarding requirements for digital assets (CoinDesk). The goal is to make the rules clearer without hindering the sector’s evolution. According to the data collected by our regulatory monitoring team, in the first weeks following the publication, the feedback received from professionals and operators focused mainly on custody, incident reporting, and insurance requirements. Industry analysts note that many responses require technical clarifications on multi-sig, asset segregation, and recovery protocols, as well as proposals to scale obligations based on the size of the operator. FCA Consultation: What’s on the Table The consultation document clarifies how to apply rules inspired by traditional finance to the crypto perimeter, balancing innovation, market integrity, and user protection. In this context, the goal is to introduce minimum standards for all firms under the supervision of the FCA, an essential step for a more transparent and secure sector, with measurable benefits for users. The proposed pillars Obligations towards consumers: assessment on the extension of the Consumer Duty – a requirement that mandates companies to provide “good outcomes” – to crypto services, with outcomes for users that are traceable and verifiable. Operational resilience: introduction of continuity requirements, incident response plans, and periodic testing to ensure the operational stability of platforms even in adverse scenarios. Financial Crime Prevention: strengthening AML/CFT measures through more stringent transaction monitoring and structured counterpart checks. Custody and safeguarding: definition of operational methods for the segregation of client assets, secure…
Share
BitcoinEthereumNews2025/09/18 05:40
[Rappler’s Best] Tony Meloto falls

[Rappler’s Best] Tony Meloto falls

FUN. Agos is a fictional Filipino child who explores the outdoors.
Share
Rappler2026/06/01 18:00

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage