Echo Protocol Hack

Reported loss $816K
Monad
Access Control

What happened

On May 19, 2026, Echo Protocol reported a security incident affecting its Echo bridge on Monad. Cointelegraph and Merkle Science separately reported that an attacker minted about 1,000 unauthorized eBTC and extracted about 11.29 WBTC (roughly $867,000) through Curvance.

Technical root cause

Merkle Science characterized the incident as an operational access-control failure: a compromised administrator EOA had uncapped minting authority without a multisignature safeguard.

How it happened

According to Merkle Science, the attacker used the administrator key to grant their own wallet minting rights, minted unbacked eBTC, deposited 45 eBTC into Curvance, borrowed WBTC, then bridged and swapped the proceeds before routing ETH through Tornado Cash.

Protocol details

Classification Yield Aggregator / Key Compromise
Protocol Type Bridge
Category Bridge Hack
Implementation language Solidity
Protocol links Website @EchoProtocol_

Market Context at Time of Hack

Token Price at Hack $0.00559487
Market Cap at Hack $1.2M
Reported loss / token market cap 69.95%
Token Categories
Asset Management DeFi Staking BNB Chain Ecosystem Aptos Ecosystem Bitcoin Ecosystem MoveVM (MVM) Binance Alpha Airdrops

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.