Axelar Says $4.67M Secret Bridge Exploit Stemmed From Forked Contract

Axelar Says $4.67M Secret Bridge Exploit Stemmed From Forked Contract

N
News Editor 01
2026-07-22 04:52:13
Axelar said the $4.67 million Secret Network exploit did not compromise Axelar or IBC itself. The issue was traced to a forked Secret-side contract that removed key minting checks, letting attackers mint unbacked assets and redeem them through legitimate bridge channels.
AxelarSecret NetworkBridge SecurityIBCExploit

Axelar Network has issued a clarification on the $4.67 million exploit tied to Secret Network, stressing that neither Axelar itself nor the Inter-Blockchain Communication protocol was compromised. Based on statements from Axelar and findings from security researcher Common Prefix, the root cause was a vulnerable smart contract on Secret that allowed attackers to mint assets without backing and then redeem them through legitimate bridge rails.

Root cause traced to a forked contract

According to Axelar, the exploited contract was a fork of the CW20-ICS20 implementation used to wrap assets arriving over IBC. In that fork, developers removed two core security checks designed to prevent unauthorized token minting. Axelar said those changes altered the contract’s trust assumptions and introduced an “infinite mint” vulnerability, yet the modified version did not go through a new security audit.

Common Prefix reached a similar conclusion in its own investigation. The firm found that the contract minted Secret-wrapped assets, or saTokens, without validating the source channel of inbound transfers. That design flaw let an attacker spin up a single-validator Cosmos chain, establish an IBC connection to the contract, and send forged packets using approved token denominations. In return, the attacker received legitimate saTokens that had no collateral behind them.

How the exploit drained escrowed funds

The incident affected seven assets: saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB, and sawstETH. After minting these unbacked wrapped assets, the attacker redeemed them through Axelar’s valid channel infrastructure and withdrew real funds held in escrow. This explains why the exploit touched bridge flows while, according to Axelar, not representing a failure of its core bridge protocol.

The vulnerability was reportedly present as far back as the contract’s original deployment in early 2023. A migration on March 5 preserved the same missing validation logic. The theft was not discovered until June 17, when a routine cross-chain transfer failed because the escrow account no longer held enough funds. Secret Network said encrypted balances made the shortfall harder to detect, and also noted that the functions verifying transfer sources had been removed during an earlier redesign.

Containment steps after discovery

After the issue was identified, Axelar disabled its connections to Secret and Secret-SNIP. Cross-chain router Squid also removed Secret Network from its interface. Axelar said firewalling and isolation measures kept the issue from spreading further, adding that no other chains, escrow accounts, channels, or core protocol components were affected.

Meanwhile, stolen assets were traced through Osmosis and Ethereum before exchanges and law enforcement became involved. Axelar said it continues to coordinate with relevant parties while keeping the affected connection offline. The broader takeaway from the case is that cross-chain failures do not always begin at the bridge layer itself; modified wrapper contracts can become a major point of failure when key trust assumptions change without renewed auditing.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.