YFarmX

Tools Crypto Exploit Tracker exploit-0042

Exploit record

Echo Protocol

Loss
$77M
Attack vector
Private Key Compromise
Chain
Monad
Sector
Yield

What happened

On 19 May 2026 an attacker used a compromised admin key to mint about 1,000 unauthorised eBTC on Echo Protocol's Monad deployment, a paper value of roughly $76.7 million, though the realised take was far smaller.

The eBTC minting contract had no multisig, timelock or mint limits, so the stolen admin key gave the attacker unilateral minting rights. Thin liquidity on Monad limited the realised proceeds to roughly $816,000 in ETH sent to Tornado Cash, plus about $3.45 million in WBTC borrowed against minted eBTC on Curvance. Echo regained control of the admin keys, burnt the remaining 955 eBTC, paused Monad cross-chain functionality and upgraded the affected contract.

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026