Secret Network Suffers $4.67 Million Bridge Exploit via Axelar Contract
Secret Network lost $4.67 million in a bridge exploit involving tokens from Axelar. An attacker exploited a smart contract vulnerability that failed to validate the origin of incoming cross-chain messages. The attacker sent fake deposit packets from a private blockchain to mint unbacked tokens on Secret, then redeemed them for real assets. Axelar has since disconnected the affected bridge connection.
Secret Network bridge exploit
▪The stolen assets included seven types of tokens: wrapped USDT, USDC, DAI, WETH, WBTC, WBNB, and wstETH.
▪The attack targeted an ICS-20-based smart contract on Secret Network used to facilitate cross-chain transfers from Axelar.
▪An exploit on Secret Network drained approximately $4.67 million worth of tokens bridged from Axelar on or before June 19, 2026.
Contract vulnerability mechanics
▪The contract also did not check if redemption requests exceeded the amount of assets available in escrow.
▪The vulnerability existed in a modified CW20-ICS20 token contract on Secret Network that processed incoming IBC transfers.
▪The contract failed to verify that incoming token transfers originated from an authentic Axelar-controlled IBC channel.
▪The flawed validation logic was traced back to public commits in 2023 and was carried forward in a March 2026 migration.
Fake IBC packet attack
▪The attacker sent fake deposit packets through a new, attacker-controlled IBC channel to Secret Network.
▪The vulnerable contract accepted the fake packets and created unbacked wrapped tokens on Secret Network.
▪The attacker created a minimal Cosmos blockchain with a single validator to send malicious packets.
▪The attacker then redeemed the unbacked tokens through the legitimate Axelar bridge mechanism, draining real assets from escrow accounts.
Emergency response measures
▪Axelar's emergency task force disconnected the affected IBC connection to Secret Network immediately after identifying the incident.
▪Recovery efforts may be complicated by Secret Network's default encryption of balances and transfers.
▪Axelar stated that its core protocol, other IBC connections, and other escrow accounts were not affected by the exploit.
Cross-chain bridge security
▪The incident highlights a recurring vulnerability in cross-chain bridges related to message validation.
▪In June 2026, a Syscoin bridge was paused after an attacker exploited a validation flaw to mint approximately 5 billion unauthorized SYS tokens.
▪In February 2026, the CrossCurve protocol lost an estimated $3 million from smart contract vulnerabilities.
Story comments
Loading comments…