
On May 18, 2026, an attacker exploited Echo Protocol on Monad by minting 1,000 fake eBTC tokens worth approximately $76.7 million on paper. However, as reported by DefiLlama, the real financial impact was significantly lower at around $816,000 in actual stolen value. The attacker stole an admin key controlling minting rights for Echo's eBTC token and used it to create fake Bitcoin-backed tokens without any real BTC backing. The exploit highlights how DeFi protocols are increasingly vulnerable to operational failures rather than smart contract bugs, with the $76 million figure serving as theater rather than actual loss. The attacker's actual profit came from converting a small portion into real collateral, borrowing real assets, and moving off-chain through liquidity arbitrage rather than vault robbery.
According to DefiLlama's 2026 hack breakdown, DeFi losses crossed $1 billion in four months, with April alone draining $634 million across 28+ incidents - the worst month on record. The biggest security threats include LayerZero bridge exploits (18%), compromised admin keys (16%), spoof tokens (14%), and private key compromises (11%). As reported by DefiLlama, operational and key-management failures now account for the majority of stolen value, with smart contract bugs barely registering. This represents a fundamental shift in how DeFi attackers are targeting protocols, with the $76 million headline figure doing its work by reminding everyone that digital Bitcoin protocols are only as secure as the people who manage their keys.
According to the post-mortem analysis, Echo Protocol made critical security mistakes that enabled the attack. The DEFAULT_ADMIN_ROLE was held by a single wallet with no safety nets, allowing whoever held the private key to mint as much eBTC as desired without delay. The contract had no time lock, no maximum supply limit, and no rate limits, enabling the attacker to mint the entire 1,000 eBTC in a single transaction. Additionally, Curvance lending protocol accepted the fake eBTC as collateral without proper verification, allowing the attacker to borrow $868,000 worth of WBTC against the fake tokens. The protocol recovered the compromised key and burned 955 of the minted tokens, containing the damage and preventing the attacker from sitting on the full $76.7 million face value.
As detailed in the report, the attacker first granted themselves admin and minter roles using the stolen key, then minted the 1,000 fake eBTC tokens. They deposited 45 eBTC ($3.45M paper value) into Curvance as collateral, which accepted the fake tokens as legitimate collateral. The attacker then borrowed 11.29 WBTC ($868K) against the fake collateral and bridged it to Ethereum. After swapping the WBTC for 384 ETH ($822K), they ran the funds through Tornado Cash to obscure the trail. The remaining 955 fake eBTC were later burned by Echo after the attack was discovered, with the $816,000 actual loss coming from the attacker's ability to convert a small portion into real assets and move off-chain quickly.
The Echo Protocol incident represents a broader trend in DeFi security, where attackers are targeting operational vulnerabilities rather than smart contract bugs. As reported by DefiLlama, 2026 has seen approximately $328.6 million lost to bridge hacks across 8 incidents, with none of these being Solidity bugs. The attack demonstrates that multisig admin control, timelocks, mint caps, rate limits, and collateral checks could have prevented this exploit. Echo got lucky that Monad's thin liquidity prevented full cashout, but future protocols may not have similar protection. The incident exposes that the trust model hasn't evolved as fast as the marketing in the BTCFi narrative, where investors need to ask the same questions about digital Bitcoin products that they'd ask about any custodian: who holds the keys, how many keys does it take to move them, and what happens when one does.