Home Blog Page 231

Echo Protocol suffers $76 million exploit in eBTC minting attack on Monad

0

The Bitcoin-focused DeFi protocol suffered an attack whereby about 1,000 unauthorized eBTC $77 million were minted on the Monad blockchain

Bitcoin treads water near pivotal monthly close while speculative tokens retreat

0

Bitcoin held near $76,800 as altcoins weakened, WLFI slid and traders watched whether the largest cryptocurrency can hold Tom Lee’s line in the sand.

Crypto Hack Hits Echo As Monad’s eBTC Market Faces Fallout

0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Echo Protocol is investigating a security incident involving its bridge on Monad after crypto on-chain analysts said an attacker minted 1,000 eBTC and used part of the position to extract WBTC liquidity through Curvance.

The first public alarm came from on-chain analyst DCF GOD, who wrote that Echo “may be hacked on Monad.” He added: “Someone minted 1k ebtc out of nowhere, max borrowed wbtc against it on Curvance, bridged, and tornado away.” A follow-up post pointed to a Monad transaction showing a 1,000 eBTC transfer on May 18 at 21:21:32 UTC.

$76M Crypto Mint Sparks Alarm

Lookonchain later mapped the reported sequence in more detail. According to the account, the attacker minted 1,000 eBTC, valued at about $76.64 million, deposited 45 eBTC worth roughly $3.45 million into Curvance, borrowed 11.3 WBTC worth about $867,000, bridged the WBTC to Ethereum, swapped it for 385 ETH worth about $821,000, and deposited the ETH into Tornado Cash. Lookonchain said the attacker still held 955 eBTC, valued at about $73.2 million.

Phylax Systems founder and CEO Odysseas Lamtzidis said the transaction trail pointed away from a Curvance lending flaw and toward a role-management compromise on the eBTC side. “Monad eBTC/Curvance trace: not a Curvance lending bug,” he wrote. “The eBTC admin granted DEFAULT_ADMIN_ROLE to 0x6A0109, who revoked admin, self-granted MINTER_ROLE, minted 1,000 eBTC, posted 45 eBTC as collateral, and borrowed ~11.296 WBTC.” Lamtzidis said the pattern “looks like admin-key/role compromise,” citing key transactions for the admin grant, mint and borrow.

Echo confirmed the incident without publishing a root-cause analysis. “We are currently investigating a security incident impacting the Echo bridge on Monad. All cross-chain transactions remain suspended while the investigation is underway. We will continue to provide timely updates through our official channels as more information becomes available.” The suspension makes the bridge the immediate operational focus, not simply the lending market that processed the collateral.

Curvance’s exposure appears to have come through the affected Echo eBTC market. Curvance paused that market while the teams investigated, and cited Curvance as saying there was no indication its smart contracts had been compromised and that its isolated-market architecture meant other markets were not affected. Also, Monad’s network itself was not affected.

Monad CEO Keone Hon wrote via X: “To clarify, the Monad network is not affected and is operating normally. Security researchers in their review have determined that ~$816,000 appears to have been stolen as a result of this exploit of Echo Protocol’s eBTC.

The incident illustrates a familiar bridge-to-lending failure pattern. Once a bridged or synthetic asset is treated as valid collateral, even a partial conversion path can turn a supply-side failure into real liquidity loss. In this case, the eBTC mint was used to borrow WBTC, move it off Monad, convert it into ETH, and route the funds through a mixer before the broader notional position was fully monetized.

Echo’s next update will need to answer several market-facing questions: whether the unauthorized eBTC has been neutralized, whether Curvance faces bad debt from the WBTC borrow, which bridge permissions or contracts were involved, and when cross-chain transactions can safely resume. Until then, the eBTC market on Monad remains the key pressure point for users trying to assess whether the incident was contained or merely slowed.

The Echo exploit also lands during a rough stretch for crypto infrastructure. On May 15, THORChain has lost more than $10 million across Bitcoin, Ethereum, BNB Chain and Base, including 36.75 BTC and roughly $7 million in other assets. Days later, the Verus-Ethereum Bridge was drained for about $11.5 million, with reports saying the attacker took 103.6 tBTC, 1,625 ETH and 147,000 USDC before consolidating the haul into roughly 5,402 ETH. Echo now gives markets another reminder that bridge design, collateral acceptance and liquidity routing remain one of DeFi’s most exposed attack surfaces.

[UPDATE from X:] Echo Protocol confirmed: “Earlier today, Echo Protocol identified unauthorized activity involving eBTC on Monad that resulted in unauthorized minting and associated fund loss. Our investigation indicates the issue originated from a compromised admin key affecting the Monad deployment. Based on current findings, approximately $816K was impacted on Monad. The Monad network itself was not impacted and continues to operate normally.

Since detecting the incident, we have been actively investigating potential cross-chain exposure, coordinating with ecosystem partners, and implementing additional precautionary measures. We have successfully regained control of our admin keys and burnt the remaining 955 eBTC that was in the attacker’s possession.”

At press time, the total crypto market cap stood at $2.54 trillion.

Total crypto market cap chart
Total crypto market cap hovers above key support | Source: TOTAL on TradingView.com

Featured image created with DALL.E, chart from TradingView.com

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Circle’s USYC Becomes Largest T-Bill Fund on BNB Chain at $2.9 Billion

0

Circle’s USYC tokenized Treasury bill fund has reached $2.9 billion in market cap, becoming the largest T-Bill fund deployment across blockchain networks.

Circle’s USYC has become the largest tokenized Treasury bill fund with a $2.9 billion market cap on BNB Chain, according to data from Token Terminal. The fund’s size significantly outpaces competitors in the growing category of on-chain T-Bill products.

There are currently 23 T-Bill fund deployments with market capitalizations exceeding $100 million, indicating substantial institutional and retail interest in tokenized fixed-income products on blockchain networks. USYC’s dominance reflects Circle’s position as a leading issuer of tokenized Treasury exposure in the DeFi ecosystem.

Sources: Token Terminal

This article was produced with the help of AI flows.

VanEck and Grayscale Push Forward With Spot BNB ETF Filings

0

VanEck and Grayscale have submitted fresh amendments to their spot BNB ETF applications, signaling active engagement with the SEC as competition intensifies for the next altcoin ETF.

VanEck and Grayscale have filed new amendments to their spot BNB ETF applications, advancing the regulatory race to bring the first Binance Coin exchange-traded fund to U.S. markets. VanEck has now submitted five amendments since its original filing. Both proposed ETFs would directly hold BNB and trade on Nasdaq if approved, according to Bloomberg ETF analyst James Seyffart, who noted the filings suggest active SEC engagement.

The amendment activity reflects the competitive dynamics in the altcoin ETF space following approvals of Bitcoin and Ethereum spot ETFs. The BNB ETF race has drawn multiple applicants seeking to capitalize on demand for exposure to the Binance ecosystem’s native token.

Both VanEck and Grayscale have excluded staking from their initial ETF proposals, citing ongoing regulatory uncertainty around staking arrangements. The decision to exclude staking functionality at launch reflects caution in how crypto asset features are treated under U.S. securities regulation.

Separately, Canary Capital updated its staked TRX ETF filing on Friday, continuing activity in the broader altcoin ETF pipeline. The SEC has yet to approve any spot altcoin ETF beyond Bitcoin and Ethereum.

This article was produced with the help of AI flows.

US Lawmakers Push Permanent CBDC Ban in Housing Bill Debate

A pair of Republican lawmakers is calling for a permanent ban on a US central bank digital currency (CBDC) to be enshrined in the 21st Century ROAD to Housing Act, as the measure is expected to come up for a vote in the US House this week. 

The bill released by the US Senate Committee on Banking, Housing and Urban Affairs in March mainly concerns revisions to federal housing programs but also includes a section banning the Federal Reserve System or any Federal Reserve bank from issuing a CBDC or similar instrument until Dec. 31, 2030.

The US House has created its own amended bill, which Congressman Mike Flood said reverses the “backdoor green light for a CBDC” and aims to make the ban permanent.

The amended legislation is expected to go to a vote in the House this week. If it passes, the bill will return to the Senate, where it could undergo further amendments. The legislation must pass both chambers before it can go to President Donald Trump’s desk to be signed into law.

Critics of CBDCs often cite their potential for misuse. The Human Rights Foundation said the benefits of CBDCs include the potential to expand financial inclusion for populations with limited access to the financial system. Drawbacks include the currency’s potential to infringe on privacy and open new avenues for government corruption, among other concerns.

Ban needs to be made permanent, representative says

US Representative Warren Davidson, a member of the House, also supported a permanent CBDC ban as the “2030 sunset works a pre-launch development period.”

“The US House of Representatives could deliver a unifying win this week with bipartisan housing affordability legislation. Instead, they currently plan to deliver a go-live date for Central Bank Digital Currency, using housing as the Trojan Horse,” he added.

Source: Warren Davidson

The American think tank The Atlantic Council’s tracker lists only three countries that have officially deployed a CBDC: Nigeria, Jamaica, and the Bahamas, while 41 others are in the pilot phase.

Alternate bills to ban a CBDC on the sidelines 

Meanwhile, Tom Emmer, the House majority whip, one of the top Republican leadership positions in Congress, is advocating for his Anti-CBDC Surveillance State Act. 

The bill passed the House on July 17 but has yet to receive full Senate approval. It aims to block the Federal Reserve from creating or issuing a CBDC.

Source: Tom Emmer

“The Chinese Communist Party uses a central bank digital currency (CBDC) to surveil and control its people. If the US adopted its own CBDC, privacy and economic freedom as we know it would cease to exist,” he said.

Related: Bank of Korea governor backs CBDCs, deposit tokens in first address

“My Anti-CBDC Surveillance State Act BANS our government from ever creating this Orwellian tool. The House passed it. Now, the Senate must act.”

Previously, Senator Mike Lee introduced the “No CBDC Act” as a standalone bill prohibiting the Fed or Treasury from issuing a CBDC. However, it stalled in Congress. 

Magazine: Bitcoin ETFs bleed $1B, Aave’s $71M ETH unfreeze bid delayed: Hodler’s Digest, May 10 – 16

CoinDesk 20 performance update: Bitcoin Cash (BCH) drops 13% as all assets decline

0

Bittensor (TAO), down 9.6% over the weekend, joined Bitcoin Cash (BCH) as an underperformer.

Bitcoin has shed $5,000 within days. The data says this selloff could worsen

0

Bitcoin has fallen about 6% from $82,000 to $76,800, but underlying data point to more than routine pullback.

Georgia Primary to Test Crypto PAC’s Support for Democratic Candidate

The Protect Progress, a political action committee (PAC) affiliated with the cryptocurrency company-backed Fairshake PAC, has spent more than $4 million attempting to help secure a win for a Georgia state representative running for the US House of Representatives.

On Tuesday, Georgia voters will decide on their candidate in the primary for the state’s 13th Congressional district, where state representative Jasmine Clark faces competition among Democrats. According to data from the Federal Election Commission, Clark has been the beneficiary of more than $4.2 million in spending on media by the Protect Progress PAC ahead of the primary, as crypto-aligned interest groups attempt to influence voters in key elections.

Source: FEC

Notably, Clark appeared to have deleted a social media post from March saying that “digital assets are the future and provide long-overdue financial tools for unbanked communities,” referencing the US Congress considering a crypto market structure bill. She also completed a questionnaire from the Coinbase-aligned organization Stand With Crypto, which said she was a candidate who “expressed strong support for establishing clear legislative and regulatory frameworks for digital assets in the United States.”

Protect Progress and its affiliates Fairshake and Defend American Jobs are expected to spend millions of dollars in 2026 to support candidates they consider will advance pro-crypto policies and opposing those who don’t. In 2024, Fairshake spent more than $130 million on media and ads, resulting in what Coinbase CEO Brian Armstrong called the “most pro-crypto Congress ever.” Coinbase is a backer of Fairshake.

Related: Crypto PACs spend $7.2M to support candidates in 5 US states ahead of elections

Not every election or party primary has been a winner for Fairshake or crypto interest groups seeking to influence voters. The PAC spent a reported $8 million opposing Illinois Lieutenant Governor Juliana Stratton in her US Senate primary, but in March more than 40% of voters chose her over candidates supported by Fairshake and Protect Progress-backed ads.

Screenshot of Stand With Crypto’s rating of Jasmine Clark. Source: Stand With Crypto

“From a Stand With Crypto perspective, we are going to do everything we can to give our advocates the tools they need to make sure that they make an informed vote and they’re able to cast their ballot on election day for the candidate that is pro-crypto they care about,” Mason Lynaugh, executive director of Stand With Crypto, told Cointelegraph on the organization’s work in 2026. “If everyone makes their voices heard […] we will have a more pro-crypto Congress than we did this past year.”

Cointelegraph sought a comment from Fairshake ahead of Tuesday’s voting but did not receive an immediate response.

Texas run-off election also getting big spending

Next week, voters in Texas’ 18th Congressional District will head to the ballot boxes to decide between Representative Al Green and Democratic candidate Christian Menefee. Protect Progress reportedly spent more than $1.5 million opposing Green in a March primary, but Menefee only secured 46% of voters compared to Green’s 44%, triggering a runoff on May 26.

FEC filings showed Protect Progress spent more than $2.8 million on media opposing Green, who while in Congress voted against legislation the industry largely supported, including the GENIUS Act and CLARITY Act. The PAC spent about the same amount supporting Menefee, who has publicly supported blockchain technology.

Magazine: The legal battle over who can claim DeFi’s stolen millions

Echo Protocol Hacked for $76.7M in Admin Key Exploit

0

Decentralized finance protocol Echo Protocol was exploited after an attacker minted about 1,000 unauthorized eBTC on the protocol, which is deployed on the Monad blockchain.

Blockchain security firm PeckShield and analytics platform Lookonchain both reported the incident on Tuesday, noting that a hacker minted 1,000 synthetic Bitcoin (eBTC) worth around $76.7 million.

“We are currently investigating a security incident impacting the Echo bridge on Monad.  All cross-chain transactions remain suspended while the investigation is underway,” Echo Protocol said on Tuesday.  

This latest exploit comes in a month that has seen at least 12 protocols compromised, including THORChain, Verus Protocol’s Ethereum bridge, Transit Finance, TrustedVolumes and Ekubo.

According to PeckShield, the attacker attempted to launder some of the loot by depositing 45 eBTC worth around $3.45 million into DeFi lending and liquidity management protocol Curvance. 

The attacker then borrowed 11.3 wrapped Bitcoin (wBTC) worth $868,000 against it, bridged the tokens to Ethereum, swapped them for ETH, and sent 384 ETH worth about $822,000 to the Tornado Cash mixing service. 

The attacker still holds 955 eBTC worth about $73 million, according to DeBank.

Echo Protocol is a Bitcoin DeFi platform focused on Bitcoin liquidity aggregation, liquid staking, restaking, and yield generation. It creates unified, liquid BTC assets such as eBTC for users to bridge and deploy in DeFi for additional yield. The protocol is deployed on Monad, a high-performance, layer-1, EVM-compatible blockchain.

The hacker still holds 95% of the stolen crypto. Source: DeBank 

Admin private key compromised 

Blockchain developer “Marioo” reported that it was not a smart contract bug, but an admin private key compromise, and the root cause was “operational, not technical.”

The eBTC contract “worked exactly as designed,” they said, adding that the vulnerabilities included a single signature for the admin role, no timelock, no minting supply cap or rate limit, and no “supply sanity check” by Curvance for the freshly minted collateral.

Related: Hackers used AI to craft zero-day attack to bypass 2FA: Google

Curvance reported that it was aware of the “anomaly” detected in the Echo eBTC market on Curvance and confirmed that there was no compromise with its own smart contracts. It paused the affected market for investigation. 

Monad co-founder Keone Hon clarified on X that “the Monad network is not affected and is operating normally.”

Meanwhile, Echo Protocol said it will provide updates through its official channels as more information becomes available. 

DeFi hacks surge in 2026

The year has been challenging for DeFi security, with dozens of protocols exploited for hundreds of millions in crypto and more than 20 protocols shuttering services. 

Two of the largest hacks this year included the exploit of the Drift Protocol, which lost $285 million, and Kelp DAO, which was exploited for $292 million in April. 

On Monday, Verus Protocol’s Ethereum bridge was exploited through a fake cross-chain transfer message that allowed a hacker to steal at least $11.6 million in crypto.

Decentralized liquidity protocol THORChain halted trading on Friday after blockchain investigator ZachXBT flagged a suspected $10 million exploit

Meanwhile, Transit Finance suffered a deprecated smart contract exploit, resulting in the loss of $1.88 million last week. 

Magazine: DeFi’s billion-dollar secret: The insiders responsible for hacks