Secret Network lost $4.67 million in a bridge exploit involving tokens from Axelar. An attacker exploited a smart contract vulnerability that failed to validate the origin of incoming cross-chain messages. The attacker sent fake deposit packets from a private blockchain to mint unbacked tokens on Secret, then redeemed them for real assets. Axelar has since disconnected the affected bridge connection.
Secret Network bridge exploit
- ▪The stolen assets included seven types of tokens: wrapped USDT, USDC, DAI, WETH, WBTC, WBNB, and wstETH
- ▪The attack targeted an ICS-20-based smart contract on Secret Network used to facilitate cross-chain transfers from Axelar
- ▪An exploit on Secret Network drained approximately $4.67 million worth of tokens bridged from Axelar on or before June 19, 2026
Contract vulnerability mechanics
- ▪The contract also did not check if redemption requests exceeded the amount of assets available in escrow
- ▪The vulnerability existed in a modified CW20-ICS20 token contract on Secret Network that processed incoming IBC transfers
- ▪The contract failed to verify that incoming token transfers originated from an authentic Axelar-controlled IBC channel
- ▪The flawed validation logic was traced back to public commits in 2023 and was carried forward in a March 2026 migration
Fake IBC packet attack
- ▪The attacker sent fake deposit packets through a new, attacker-controlled IBC channel to Secret Network
- ▪The vulnerable contract accepted the fake packets and created unbacked wrapped tokens on Secret Network
- ▪The attacker created a minimal Cosmos blockchain with a single validator to send malicious packets
- ▪The attacker then redeemed the unbacked tokens through the legitimate Axelar bridge mechanism, draining real assets from escrow accounts
Emergency response measures
- ▪Axelar's emergency task force disconnected the affected IBC connection to Secret Network immediately after identifying the incident
- ▪Recovery efforts may be complicated by Secret Network's default encryption of balances and transfers
- ▪Axelar stated that its core protocol, other IBC connections, and other escrow accounts were not affected by the exploit
Cross-chain bridge security
- ▪The incident highlights a recurring vulnerability in cross-chain bridges related to message validation
- ▪In June 2026, a Syscoin bridge was paused after an attacker exploited a validation flaw to mint approximately 5 billion unauthorized SYS tokens
- ▪In February 2026, the CrossCurve protocol lost an estimated $3 million from smart contract vulnerabilities
Story comments
Loading comments…