Ecoprotocol $76.7MHack
⚠️ Echo Protocol Bridge Exploited $76.7M in eBTC Minted From Thin Air
Breaking today, May 19, 2026:
Echo Protocol, a Bitcoin DeFi platform deployed on the Monad blockchain, suffered a security incident after an attacker minted approximately 1,000 eBTC worth around $76.7 million without proper backing.
According to PeckShield, the attacker deposited 45 eBTC worth about $3.45 million into DeFi lending protocol Curvance, borrowed 11.29 WBTC, bridged the assets to Ethereum, swapped for ETH and routed 384 ETH to Tornado Cash.
Critical context on the numbers: The $76.7 million figure reflects the notional value of eBTC minted not the confirmed amount extracted from the ecosystem.
Preliminary security review places the actual stolen value closer to $816,000, aligned with the visible Tornado Cash route.
The root cause is striking: a developer confirmed this was not a smart contract bug but an admin private key compromise an operational failure. Core vulnerabilities included a single signature admin role, no timelock, no minting supply cap, and no supply sanity check by Curvance on freshly minted collateral.
Monad confirmed the underlying network is operating normally and is unaffected.
💡 Beginner's Corner Notional Value vs. Actual Loss in DeFi Exploits:
When an attacker mints unbacked tokens, the "notional value" refers to the market price of those tokens but the actual damage depends on how much real liquidity they can extract before the protocol freezes.
In this case, the BTC contract worked exactly as designed the failure was entirely operational, not technica underlining that code audits alone cannot prevent human layer security failures.
💬 Should DeFi protocols be required to enforce multi-sig admin roles and timelocks as a baseline standard before launch or does that slow down innovation too much?
#Ecoprotocol $76.7MHack
#DeFiSecurity #CryptoHack #DYOR | Educational content only | Not financial advice