The Bitcoin liquidity protocol Echo Protocol's deployment on the Monad chain has encountered a security incident. An attacker first minted 1,000 eBTC without authorization, then used a portion of them as collateral to borrow assets and transfer them across chains. The project team stated that, based on current investigation results, the actual amount affected is approximately $816,000.
The attack path involves forging and cross-chain operations.
According to researchers cited by on-chain security firm PeckShield, the attackers minted approximately $76.7 million worth of eBTC and deposited 45 of them into Curvance. Subsequently, the attackers borrowed approximately 11.29 WBTC, transferred them to Ethereum, converted them into ETH, and finally transferred 384 ETH into Tornado Cash.
Echo Protocol later confirmed on social media that the issue stemmed from a compromised management key affecting Monad deployments. The team stated that the Monad network itself was unaffected and continues to operate normally.
The project team stated that they have reclaimed management authority.
Echo Protocol stated that the team has regained control of the management keys and destroyed the remaining 955 eBTC held by the attackers. The project team also emphasized that this incident appears to be limited to the Monad deployment, and no evidence of intrusion on the Aptos side has been found.
The project team also clarified that eBTC on Monad and aBTC on Aptos are two separate assets and cannot be directly bridged. Currently, the Aptos-side risk exposure is approximately $71,000, distributed across the Echo lending market and Hyperion liquidity pools; no financial losses have been confirmed at this time.
Cross-chain functionality has been suspended.
As an emergency measure, Echo Protocol has suspended cross-chain functionality for Monad deployments and completed relevant contract upgrades to restrict affected operations and strengthen sensitive permission controls. Although no anomalies have been found on the Aptos side, the team has suspended Aptos bridging functionality and discontinued the Echo Aptos Lending service.
The project team also stated that it is upgrading its EVM series bridging deployment to further strengthen cross-chain control and reduce operational risks.
This incident once again exposes the reliance of DeFi protocols on off-chain infrastructure and centralized key management. Recently, THORChain, TrustedVolumes, and KelpDAO have also experienced security incidents, bringing renewed attention to the operational and access control risks of DeFi protocols.











