
An attacker successfully exploited Echo Protocol's Monad bridge, minting 1,000 eBTC worth approximately ₹6,200 crore ($76.7 million) according to reports from PeckShield. The exploiter then routed over $821,700 in stolen ETH through Tornado Cash, as detailed by on-chain analyst dcfgod. The attack involved depositing 45 eBTC worth $3.45 million into Curvance, borrowing 11.29 wrapped Bitcoin (WBTC), bridging the assets to Ethereum, and swapping them for ETH before sending 384 ETH to Tornado Cash. As per ChainCatcher report, the attacker strategically used the Monad network vulnerability to execute this sophisticated cross-chain arbitrage scheme. What stands out immediately is that the same basic technique was used to drain Curvance earlier in the year, demonstrating that the playbook is being recycled across attacks.
Curvance paused the affected market while Echo Protocol suspended all cross-chain transactions as a precautionary measure. According to Curvance's status update on X, the platform detected an anomaly in the Echo eBTC market at approximately 6:00 PM EST. The company confirmed there was no indication of compromise with Curvance's smart contracts, and due to the fully isolated market architecture, no other markets were impacted. Monad CEO Keone Hon clarified that the breach did not impact the Monad network, with security researchers determining approximately $816,000 was stolen as a result of the exploit. Echo Protocol has since halted all cross-chain transactions as a precautionary measure to prevent further exploitation.
The Echo Protocol exploit represents the third major DeFi hack in five days, highlighting ongoing security risks across the decentralized finance sector. As reported by PeckShield, the previous breaches included a THORChain vault breach on May 15 that drained more than $10.8 million across four blockchains, followed by an exploit of the Verus-Ethereum Bridge three days later, in which attackers drained roughly $11.58 million in digital assets. These concentrated security incidents have brought May's running tally of crypto hacks to 14, demonstrating the persistent systemic security challenges facing the DeFi ecosystem. The recent spate of attacks underscores the urgent need for enhanced security measures and protocol hardening across the sector, with the market now treating these as operating costs rather than surprises.
The recurring nature of these attacks points to fundamental architectural failures in cross-chain bridge infrastructure rather than sophisticated coding errors. As OpenZeppelin security firm summarized, $292 million was lost at Kelp DAO in mid-April due to a single-signer validator on a LayerZero bridge that shouldn't have had unilateral authority. The Verus-Ethereum bridge exploit involved an attacker submitting a forged Merkle proof that convinced the bridge to release real funds, while THORChain's compromise involved a compromised node feeding false data that the system acted upon. These incidents demonstrate that cross-chain bridges are asking fundamental validation questions - did this transaction really happen on the other chain? - and answering them with mechanisms that can be tricked by someone who knows how to forge the right documents. The pattern suggests that attackers are becoming well-funded, patient repeat offenders rather than script kiddies, with Lazarus-linked operators appearing across multiple major incidents this year.