Echo Protocol Hack
What happened
On May 19, 2026, Echo Protocol reported a security incident affecting its Echo bridge on Monad. Cointelegraph and Merkle Science separately reported that an attacker minted about 1,000 unauthorized eBTC and extracted about 11.29 WBTC (roughly $867,000) through Curvance.
Merkle Science characterized the incident as an operational access-control failure: a compromised administrator EOA had uncapped minting authority without a multisignature safeguard.
How it happened
According to Merkle Science, the attacker used the administrator key to grant their own wallet minting rights, minted unbacked eBTC, deposited 45 eBTC into Curvance, borrowed WBTC, then bridged and swapped the proceeds before routing ETH through Tornado Cash.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.