Impact on Curvance eBTC/WBTC Users
Published 7/5/2026, 6:13:13 AM
The Echo Protocol exploit, which occurred on May 18, 2026, has already directly impacted Curvance eBTC/WBTC users on the Monad network. The "exploit silence" refers to a critical operational failure where a compromised admin key allowed for the minting of unbacked tokens without triggering protocol-level safeguards. This resulted in approximately $870,000 in realized bad debt within Curvance.
Impact on Curvance eBTC/WBTC Users
While the attacker minted a notional $76.7 million in fraudulent eBTC, the actual damage to the Curvance ecosystem was limited by the thin liquidity available on the Monad network at the time of the attack.
| Metric | Value / Status |
|---|---|
| Realized Bad Debt | ~$870,000 (11.29 WBTC) |
| Fraudulent eBTC Minted | 1,000 eBTC (~$76.7M notional) |
| Market Status | PAUSED (Withdrawals/Adjustments disabled) |
| Curvance Architecture | Isolated Market (Contained to eBTC/WBTC pool) |
| Recovery Status | 955 fraudulent eBTC burned; bad debt resolution pending |
The "Exploit Silence" Mechanism
The vulnerability was not a code bug in Curvance, but rather a systemic failure in how Echo Protocol managed its administrative roles and how Curvance verified collateral backing.
- Admin Key Compromise: The attacker gained the
DEFAULT_ADMIN_ROLEon the Echo Protocol eBTC contract, allowing them to grant themselvesMINTER_ROLEand create tokens out of thin air. - Operational Silence: The lack of a multisig or timelock meant the exploit occurred instantly without any "cooling off" period that would have allowed for manual intervention.
- Oracle/Supply Gap: Curvance's oracles reported the price of eBTC correctly, but the protocol lacked a "sanity check" to verify if the total supply of eBTC was actually backed 1:1 by Bitcoin before accepting it as collateral.
Current Risks for Users
If you are a user with positions in the Curvance eBTC/WBTC market on Monad, your assets are currently affected by the following:
- Liquidity Lock: The market is PAUSED. Users cannot withdraw WBTC or eBTC until Curvance and Echo Protocol finalize a recovery plan.
- Bad Debt Socialization: There is a risk that the $870,000 deficit (the WBTC drained by the attacker) may be socialized among eBTC suppliers, meaning users might receive less than 100% of their initial deposits back.
- Counterparty Risk: The incident has highlighted that eBTC's security is entirely dependent on Echo Protocol's private key management. While Echo has regained control of its admin keys, the protocol is currently viewed as high-risk.
Resolution Progress
Echo Protocol has successfully regained control of the compromised keys and burned the remaining 955 fraudulent eBTC that the attacker was unable to offload due to Monad's liquidity constraints. Curvance is currently investigating whether the bad debt will be covered by the protocol treasury, a bailout from Echo Protocol, or through other recovery mechanisms.
Note: Curvance’s smart contracts were not compromised; the protocol functioned as designed by isolating the risk to the specific eBTC pool, preventing a total protocol drain.