ECHO Token Plunges After $76M Admin Key Exploit

Echo Protocol lost $76 million when a compromised admin key enabled unauthorized minting of 1,000 eBTC tokens on the Monad blockchain on May 19 2026.

Share
ECHO Token Plunges After $76M Admin Key Exploit

Hero illustration for article: ECHO Token Plunges After $76M Admin Key Exploit

Summary

  • Echo Protocol lost $76 million when a compromised admin key enabled unauthorized minting of 1,000 eBTC tokens on the Monad blockchain on May 19 2026.
  • The Echo Protocol hack formed part of $98 million in May 2026 DeFi losses across three incidents tied to admin key failures.
  • 2026 DeFi losses exceeded $1 billion in four months, driven largely by access control lapses rather than complex code exploits.

Echo Protocol lost $76 million on May 19 2026. A compromised admin key let an attacker mint 1,000 fake eBTC tokens on Monad. The attacker borrowed $3.45 million in wrapped bitcoin right after.

The hack crashed the $ECHO token price. It also paused the Monad bridge.

This case shows the risks that come with weak key controls on new layer-1 chains.

Context

Admin key failures keep hitting DeFi projects in 2026. Echo Protocol now joins THORChain and Verus in that group. Basic access slips, not fancy code bugs, caused the drains.

Newer chains leave teams with too much centralized power over minting and bridges. Losses topped $1 billion in the first four months alone. Bridges and yield tools keep falling to the same simple attacks.

Details

The attacker used one leaked key to mint eBTC with no on-chain checks. Reports confirm the move happened on Monad and led straight to the $3.45 million WBTC borrow.

THORChain and Verus suffered similar key leaks. Those cases pushed May totals to $98 million. Most turned out to be stolen keys rather than smart-contract flaws.

"The attacker used a compromised admin key to mint tokens, then borrowed wrapped bitcoin (WBTC) worth $3.45 million against funds in the money ..."

, Coindesk (https://www.coindesk.com/business/2026/05/19/echo-protocol-suffers-usd76-million-exploit-in-ebtc-minting-attack-on-monad)

One bad key can wipe out the safeguards teams thought they had built.

Outlook

Monad teams and other new L1 projects will likely shift to multi-sig setups and timelocks soon. The Echo hack should push everyone to review how they store admin keys and trigger bridge pauses.