Echo Protocol·Crypto / Web3·
Unauthorized minting caused approximately $816,000 in impact.
Echo Protocol confirmed that a compromised admin key caused unauthorized eBTC minting and approximately $816,000 in impact. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: Compromised admin key
- Consequence
- Reported: Unauthorized minting caused approximately $816,000 in impact.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Echo Protocol
- Industry
- Crypto / Web3
- Disclosed
- Affected asset
- Echo Protocol Monad deployment
- Reported impact
- Asset theft
- Attached evidence
- 4 independent domains · 7 sources
2)Evidence-backed incident path
- 01
Reported cause
Compromised admin key
ConfidenceSecondaryExact excerpt
E1“our investigation indicates the issue originated from a compromised admin key affecting the Monad deployment”
decrypt.co · May 19 - 02
Reached
Echo Protocol Monad deployment
ConfidenceSecondaryExact excerpt
E2“a compromised admin key affecting the Monad deployment”
decrypt.co · May 19 - 03
Observed
Unauthorized minting caused approximately $816,000 in impact.
ConfidenceProbableExact excerpt
E3“unauthorized eBTC minting and approximately $816,000 in impact”
decrypt.co · May 19
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The supplied sources do not provide a primary source for the consequence
- That a Defence review would have prevented this incident
4)Relevance to your product
A single protocol invariant can carry the weight of the complete asset path.
This pattern applies when…
- Products that authorize minting or asset transfers through privileged protocol keys.
Diagnostic questions
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
This incident does not establish your product's risk.
5)Sector context — Crypto / Web3
- 0 incident threads
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 15 incident threads
- 15 incident threads
- 6 incident threads
- 15 incident threads
- 17 incident threads
- 14 incident threads
- 16 incident threads
- 26 incident threads
- Same incident family
- 98 Protocol exploit
- Confirmed share
- 14% 18 confirmed · 108 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Crypto / Web3 in Radar →6)Defence control mapping
Context-only control area
Protocol and contract control area
- Do value and authorization invariants hold across every contract path?
- Can one actor manipulate pricing, accounting or bridge state out of sequence?
- Are privileged operations bounded under adversarial composition?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
7 attached sources across 4 independent domains. No attached source is marked as an organization or regulator primary source.