BTCFi Protocol Echo Under Attack on Monad, eBTC Market Exploited

icon币界网
Share
AI summary iconSummary
On-chain news reveals that the BTCFi protocol Echo was attacked on Monday, with the exploit targeting the eBTC market on Monad. The attacker minted 1,000 eBTC, deposited 45 eBTC on Curvance, and borrowed 11.29 WBTC ($867,700). The funds were bridged to Ethereum, converted to ETH, and sent to Tornado Cash. The attacker still holds 955 eBTC ($73.2M). Monad confirmed the exploit but stated the network remained unaffected. Curvance paused the Echo eBTC market, and a protocol update is expected to address the vulnerability.
CoinDesk reports:

The decentralized finance (DeFi) protocol Echo, focused on Bitcoin, was attacked on Monday, marking the latest in a series of attacks on DeFi this year. The root cause of the attack has not yet been determined.

The vulnerability was initially discovered by an anonymous cryptocurrency influencer. Around 5:55 PM Eastern Time on Monday, DCF God posted the news on X. Other on-chain analysis accounts on the social media platform also shared the discovery and provided additional details.

According to ChainLens, the attacker minted 1,000 eBTC (Bitcoin liquidity tokens issued by Echo Protocol on Monad) and deposited 45 eBTC as collateral into the DeFi lending protocol Curvance, borrowing approximately 11.29 WBTC, worth around $867,700 at the time.

The attacker then bridged the WBTC to Ethereum and exchanged these tokens for ETH. The 385 ETH were transferred to the cryptocurrency mixer Tornado Cash.

According to reports, the attacker still holds 955 eBTC, worth $73.2 million. Lookonchain founder Nick Sawinyh wrote in a post: “The remaining 99% of the fake supply is held in the attacker’s wallet, as Monad’s lending and decentralized exchange (DEX) depth can no longer accommodate more.” wrote

Monad and Curvance subsequently acknowledged the vulnerability. Monad co-founder Keone Honsaid its security researchers are currently investigating the incident, while assuring that the network itself remains unaffected.

Hon added in a follow-up post: “Security researchers determined after review that approximately $816,000 appears to have been stolen due to this exploit of [Echo Protocol's] eBTC.”

Meanwhile, Curvance wrote that its fully independent market architecture protected other markets from being affected, and there is no indication of any compromise in its smart contracts. Curvance also stated that, as a precaution, it has suspended the affected Echo eBTC market.

Echo Protocol is a multi-chain BTCFi protocol initially launched as a Bitcoin liquidity and yield platform, with significant presence on Aptos.

Before the Echo vulnerability incident, 13 security breaches had already occurred this month in DeFi protocols. DeFi Llama includes the exploitation of Verus’s Ethereum bridge, resulting in a loss of $11.6 million, which occurred on May 17.

This is a developing news story.


Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.