Elevated risk — May 2026 admin key exploit on a sister deployment, 90% TVL decline since June 2026, and apparent Aptos liquidity withdrawal signal acute viability concerns. The dual Chainlink+Pyth oracle (August 2025) is a positive structural improvement.
Risk Breakdown
Top Risks
Admin key exploit risk — In May 2026 a compromised admin key on Echo's Monad deployment allowed unauthorized minting of 1,000 eBTC (~$76.7M notional, ~$816K realized loss). The Aptos post-exploit audit found no current compromise, but no publicly confirmed multisig or timelock protects Aptos contracts from the same control-pattern risk.
Protocol viability on Aptos — TVL collapsed from $46M (June 2026) to approximately $4.3M (July 2026), driven by the protocol withdrawing its own liquidity. Echo may be deprioritizing or winding down its Aptos deployment.
BTCFi cross-chain dependency — Echo's integration of BTC on Aptos via aBTC introduces bridge dependencies. A bridge exploit could create unbacked collateral in lending markets.
Thin Aptos ecosystem liquidity — At approximately $4M TVL, the protocol lacks sufficient liquidity depth to absorb large liquidation cascades during market stress.
Frequently Asked Questions
Is Echo Lending safe to use?
What are the main risks of using Echo Lending?
What is Echo Lending's risk score breakdown?
How does Echo Lending compare to other Lending protocols?
Has Echo Lending ever been hacked or exploited?
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.