Axelar Network has confirmed a security incident involving its bridge connection to Secret Network, with about $4.67 million in tokens stolen during transfers into Secret. The team said the issue was traced to Secret's ICS-20 smart contract and stated that Axelar's core protocol was not affected.
In its announcement on X, Axelar said the attack was limited to the specific route used to bridge assets from Axelar into Secret through the Cosmos IBC framework. It added that no other IBC connections were impacted, Secret's native token was not affected, and the rest of Axelar's integrations remained intact.
The exploit was isolated to a Secret-side contract
According to Axelar's initial investigation, the vulnerability was found in the ICS-20 contract on the Secret Network side. That contract is used to process assets bridged from Axelar into Secret through Cosmos IBC. Axelar drew a clear line between the affected integration path and its own core infrastructure.
The distinction matters. The team's statement was aimed at calming concerns that the attack had spread across the wider Axelar protocol, saying the damage was confined to a specific cross-chain route rather than the broader network.
Emergency shutdown hits Secret-related connections
After detecting abnormal fund flows, Axelar's emergency committee stepped in and disabled all cross-chain connections related to Secret and Secret-SNIP. The move was intended to stop any additional transfers and contain the incident before more assets could be moved.
Axelar also said it is working with cryptocurrency exchanges in an effort to intercept and freeze the stolen funds. At the same time, the team has reported the case to law enforcement and said it plans to publish a detailed post-mortem covering the technical details of the smart contract exploit.
Another breach puts bridge infrastructure under pressure
Cross-chain bridges have repeatedly been targeted in major exploits, and this case adds another incident to that record. Based on Axelar's current disclosures, the central issue is not the protocol core but the security of a specific connected contract path. For users moving assets across chains, that difference is critical.

