Crypto Hack Hits Echo As Monad’s eBTC Market Faces Fallout

bitcoinistОпубликовано 2026-05-19Обновлено 2026-05-19

Введение

Echo Protocol is investigating a security incident on Monad involving its eBTC bridge. An attacker, via a compromised admin key, minted 1,000 eBTC (worth ~$76.64M), used 45 eBTC as collateral on Curvance to borrow ~11.3 WBTC (~$867K), bridged the WBTC to Ethereum, swapped it for ETH, and laundered funds through Tornado Cash. The attacker still held 955 eBTC. Echo suspended cross-chain transactions and later confirmed it regained control, burning the attacker's remaining eBTC. The exploit resulted in an estimated $816K loss, affected the eBTC market, but did not compromise the Monad network or Curvance's core contracts.

Echo Protocol is investigating a security incident involving its bridge on Monad after crypto on-chain analysts said an attacker minted 1,000 eBTC and used part of the position to extract WBTC liquidity through Curvance.

The first public alarm came from on-chain analyst DCF GOD, who wrote that Echo “may be hacked on Monad.” He added: “Someone minted 1k ebtc out of nowhere, max borrowed wbtc against it on Curvance, bridged, and tornado away.” A follow-up post pointed to a Monad transaction showing a 1,000 eBTC transfer on May 18 at 21:21:32 UTC.

$76M Crypto Mint Sparks Alarm

Lookonchain later mapped the reported sequence in more detail. According to the account, the attacker minted 1,000 eBTC, valued at about $76.64 million, deposited 45 eBTC worth roughly $3.45 million into Curvance, borrowed 11.3 WBTC worth about $867,000, bridged the WBTC to Ethereum, swapped it for 385 ETH worth about $821,000, and deposited the ETH into Tornado Cash. Lookonchain said the attacker still held 955 eBTC, valued at about $73.2 million.

Phylax Systems founder and CEO Odysseas Lamtzidis said the transaction trail pointed away from a Curvance lending flaw and toward a role-management compromise on the eBTC side. “Monad eBTC/Curvance trace: not a Curvance lending bug,” he wrote. “The eBTC admin granted DEFAULT_ADMIN_ROLE to 0x6A0109, who revoked admin, self-granted MINTER_ROLE, minted 1,000 eBTC, posted 45 eBTC as collateral, and borrowed ~11.296 WBTC.” Lamtzidis said the pattern “looks like admin-key/role compromise,” citing key transactions for the admin grant, mint and borrow.

Echo confirmed the incident without publishing a root-cause analysis. “We are currently investigating a security incident impacting the Echo bridge on Monad. All cross-chain transactions remain suspended while the investigation is underway. We will continue to provide timely updates through our official channels as more information becomes available.” The suspension makes the bridge the immediate operational focus, not simply the lending market that processed the collateral.

Curvance’s exposure appears to have come through the affected Echo eBTC market. Curvance paused that market while the teams investigated, and cited Curvance as saying there was no indication its smart contracts had been compromised and that its isolated-market architecture meant other markets were not affected. Also, Monad’s network itself was not affected.

Monad CEO Keone Hon wrote via X: “To clarify, the Monad network is not affected and is operating normally. Security researchers in their review have determined that ~$816,000 appears to have been stolen as a result of this exploit of Echo Protocol’s eBTC.

The incident illustrates a familiar bridge-to-lending failure pattern. Once a bridged or synthetic asset is treated as valid collateral, even a partial conversion path can turn a supply-side failure into real liquidity loss. In this case, the eBTC mint was used to borrow WBTC, move it off Monad, convert it into ETH, and route the funds through a mixer before the broader notional position was fully monetized.

Echo’s next update will need to answer several market-facing questions: whether the unauthorized eBTC has been neutralized, whether Curvance faces bad debt from the WBTC borrow, which bridge permissions or contracts were involved, and when cross-chain transactions can safely resume. Until then, the eBTC market on Monad remains the key pressure point for users trying to assess whether the incident was contained or merely slowed.

The Echo exploit also lands during a rough stretch for crypto infrastructure. On May 15, THORChain has lost more than $10 million across Bitcoin, Ethereum, BNB Chain and Base, including 36.75 BTC and roughly $7 million in other assets. Days later, the Verus-Ethereum Bridge was drained for about $11.5 million, with reports saying the attacker took 103.6 tBTC, 1,625 ETH and 147,000 USDC before consolidating the haul into roughly 5,402 ETH. Echo now gives markets another reminder that bridge design, collateral acceptance and liquidity routing remain one of DeFi’s most exposed attack surfaces.

[UPDATE from X:] Echo Protocol confirmed: “Earlier today, Echo Protocol identified unauthorized activity involving eBTC on Monad that resulted in unauthorized minting and associated fund loss. Our investigation indicates the issue originated from a compromised admin key affecting the Monad deployment. Based on current findings, approximately $816K was impacted on Monad. The Monad network itself was not impacted and continues to operate normally.

Since detecting the incident, we have been actively investigating potential cross-chain exposure, coordinating with ecosystem partners, and implementing additional precautionary measures. We have successfully regained control of our admin keys and burnt the remaining 955 eBTC that was in the attacker’s possession.”

At press time, the total crypto market cap stood at $2.54 trillion.

Total crypto market cap hovers above key support | Source: TOTAL on TradingView.com

Связанные с этим вопросы

QWhat was the core vulnerability exploited in the Echo Protocol hack on Monad?

AThe core vulnerability was a role-management compromise on the eBTC side of the Echo Protocol. Specifically, the admin key was compromised, allowing an unauthorized actor to grant themselves the MINTER_ROLE, which was then used to mint 1,000 unauthorized eBTC tokens.

QWhat were the key steps the attacker took to extract value from the exploit?

AThe attacker first minted 1,000 eBTC. Then, they deposited 45 eBTC as collateral on the lending protocol Curvance, borrowed approximately 11.3 WBTC against it, bridged the WBTC to the Ethereum network, swapped it for 385 ETH, and finally deposited the ETH into the Tornado Cash mixer.

QWhat was the estimated financial impact of this security incident?

AApproximately $816,000 was directly stolen and moved off-chain. The attacker initially minted 1,000 eBTC valued at about $76.64 million, but the majority (955 eBTC worth ~$73.2 million) was later burnt by the Echo team after they regained control.

QAccording to the article, was the Monad network itself or Curvance's core contracts compromised?

ANo. Both Monad's network and Curvance's core smart contracts were not compromised. The incident was isolated to a compromise of Echo Protocol's admin key for its eBTC deployment on Monad. Curvance's isolated-market architecture also prevented the issue from spreading to its other markets.

QWhat actions did Echo Protocol take in response to the incident?

AEcho Protocol suspended all cross-chain transactions on its bridge. They coordinated with partners, investigated potential cross-chain exposure, implemented precautionary measures, successfully regained control of their compromised admin keys, and burnt the remaining 955 eBTC that was in the attacker's possession.

Похожее

Fei-Fei Li's Team Clarifies the Concept of 'World Models', Sora Merely a Renderer

"World Models" has become a widely used yet confusing term in AI. To address this, a team led by Fei-Fei Li and World Labs proposed a functional taxonomy based on the Partially Observable Markov Decision Process framework. This taxonomy categorizes systems called "world models" into three distinct projections: Renderers, Simulators, and Planners. Renderers, like OpenAI's Sora and other video generation models, focus on producing photorealistic visual outputs for human perception. They prioritize visual fidelity over physical accuracy. Simulators, such as NVIDIA Omniverse, aim to compute precise future environmental states for computational tasks like engineering analysis or digital twins. Planners, like Vision-Language-Action models, take in observations and goals to output executable actions for robots or agents. The article clarifies that most current "world models," including Sora, are primarily Renderers. They generate convincing visuals but lack the core ability to simulate state transitions based on actions, a key requirement for a true world model in classic reinforcement learning definitions. This conceptual confusion has practical implications, leading to potential misalignment in technology selection, investment, and public understanding of AI capabilities. Clear categorization is crucial. It helps enterprises avoid costly mistakes (e.g., using a renderer for robot training), allows investors to accurately assess markets, and enables researchers to build comparable benchmarks. While future systems may integrate these functions, recognizing current boundaries is essential for honest assessment and progress.

marsbit1 ч. назад

Fei-Fei Li's Team Clarifies the Concept of 'World Models', Sora Merely a Renderer

marsbit1 ч. назад

Bloomberg Uncovered: How Do China's Wealthy Circumvent the Annual $50,000 Limit to Transfer Assets?

**Summary: How Wealthy Chinese Circumvent $50,000 Annual Foreign Exchange Limits** Despite China's strict capital controls, including an annual $50,000 per person foreign exchange quota, an estimated $150 billion in funds still leaves the country annually via various gray and underground channels. This report outlines the evolution of China's "capital wall" and the methods used to bypass it. **The Evolving Capital Controls:** * **Foundation (1994):** The system of "current account convertibility with strict capital account controls" was established. * **Quota Set (2007):** The $50,000 individual annual forex purchase limit was formalized. * **Crackdown Begins (2015-2017):** Following market volatility, enforcement tightened. Banks were required to scrutinize transactions, and channels like using UnionPay cards for Hong Kong insurance premiums or buying overseas property were blocked. * **Digital & Legal Upgrades (2024-2026):** Enhanced algorithms now flag suspicious patterns (e.g., "smurfing"). The Common Reporting Standard (CRS) provides Chinese tax authorities with data on citizens' offshore accounts. Unlicensed cross-border brokers have been targeted. **Five Primary Methods for Moving Capital:** 1. **Underground Banking / "Hawala" (Duiqiao):** The largest-scale method. No money crosses borders. Clients pay RMB to a domestic account; an overseas associate deposits equivalent foreign currency into the client's offshore account. Risks include high fees, account freezes, and legal penalties. 2. **"Smurfing" or "Ant Moving":** Using multiple individuals' $50,000 quotas to pool funds for one offshore recipient. Increasingly detected by anti-money laundering algorithms. 3. **Trade Invoice Manipulation:** Businesses over-invoice imports or under-invoice exports via offshore shell companies, creating a pretext to transfer excess funds abroad under the guise of trade. 4. **Channel Migration:** After a crackdown on internet brokers, funds flow toward more compliant but costly channels like major banks' cross-border wealth management services or Qualified Domestic Institutional Investor (QDII) quotas. 5. **Structural Arrangements:** High-net-worth individuals use complex, high-cost legal structures involving offshore trusts, insurance, and investment migration programs to transfer asset ownership. **Regulatory Response: Focusing on People, Not Just Money** The current strategy extends oversight from enterprises to **individual residents**. Tools like CRS allow retroactive visibility into offshore assets. Cryptocurrencies, once seen as a potential loophole, are now actively monitored and prosecuted as an illegal channel. The underlying driver remains: with significant wealth concentrated among millions of affluent households seeking diversification amid domestic economic shifts, the incentive to move assets offshore persists despite regulatory barriers.

marsbit1 ч. назад

Bloomberg Uncovered: How Do China's Wealthy Circumvent the Annual $50,000 Limit to Transfer Assets?

marsbit1 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.4k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.02

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片