Echo Protocol Security Incident on Monad Chain Involves Unauthorized eBTC Minting

icon币界网
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Echo Protocol faced on-chain repercussions following a security breach on the Monad chain, which resulted in the unauthorized minting of 1,000 eBTC. The attackers used 45 eBTC as collateral to borrow 11.29 WBTC, later converting it to 384 ETH via Ethereum and Tornado Cash. The team confirmed that a compromised management key was the cause, has since regained control, destroyed 955 eBTC, and paused cross-chain functions. A protocol update is currently in progress to address vulnerabilities related to key management and infrastructure risks.
CoinDesk reports:

The Bitcoin liquidity protocol Echo Protocol suffered a security incident on the Monad chain. The attacker first unauthorized minted 1,000 eBTC, then used a portion as collateral to borrow assets and transferred them cross-chain. The project team stated that, based on current investigations, the actual affected amount is approximately $8.16 million.

The attack vector involves minting and cross-chain transfers.

On-chain security firm PeckShield, citing researcher information, stated that the attacker minted approximately $76.7 million worth of eBTC and deposited 45 eBTC into Curvance. Subsequently, the attacker borrowed about 11.29 WBTC, transferred them to Ethereum, converted them to ETH, and ultimately sent 384 ETH to Tornado Cash.

The Echo Protocol later confirmed on social media that the issue stemmed from compromised administrative keys affecting Monad's deployment. The team stated that the Monad network itself was unaffected and continues to operate normally.

The project team claims to have regained management control.

Echo Protocol stated that the team has regained control of the management keys and has destroyed the remaining 955 eBTC held by the attacker. The project team also emphasized that, based on current findings, the incident is limited to the Monad deployment, with no evidence of compromise on Aptos.

The project team also clarified that eBTC on Monad and aBTC on Aptos are two separate assets that cannot be directly bridged. The current exposure on the Aptos side is approximately $71,000, spread across the Echo lending market and the Hyperion liquidity pool, with no confirmed loss of funds to date.

Cross-chain functionality has been suspended.

As an emergency measure, Echo Protocol has suspended the cross-chain functionality of the Monad deployment and completed the associated contract upgrade to restrict affected operations and enhance control over sensitive permissions. Although no anomalies have been detected on the Aptos side, the team has also suspended the Aptos bridge and terminated the Echo Aptos Lending service.

The project team also stated that they are upgrading their EVM series bridge deployment to further enhance cross-chain control and reduce operational risk.

This incident once again highlights DeFi protocols' reliance on off-chain infrastructure and centralized key management. Recently, THORChain, TrustedVolumes, and KelpDAO have also experienced security incidents, once again drawing attention to the operational and permission management risks of DeFi protocols.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.