Axelar Says Secret-Side ICS-20 Contract Incident Led to About $4.67 Million in Token Theft

Axelar Says Secret-Side ICS-20 Contract Incident Led to About $4.67 Million in Token Theft

N
News Editor
2026-06-20 01:00:52
Axelar Network said it identified an incident affecting assets bridged from Axelar to Secret Network through IBC, with about $4.67 million in tokens stolen. The issue was limited to the ICS-20 smart contract on the Secret side, while Axelar’s core protocol and other integrations were not affected.
AxelarSecret NetworkIBCICS-20Common Prefix

ChainCatcher reported that Axelar Network said on X that it had identified an incident affecting assets bridged from the Axelar chain to Secret Network through IBC. Around $4.67 million worth of tokens were stolen. Based on the information currently available to Axelar, the issue was limited to the ICS-20 smart contract on the Secret side. That contract is part of the Cosmos IBC connection between Secret and Axelar and is used to bridge assets from Axelar to Secret.

Secret and Secret-SNIP connections disabled

Axelar said its emergency committee disabled the Secret and Secret-SNIP connections immediately after discovering the incident. The team is contacting relevant exchanges and law enforcement agencies. Axelar described the incident as limited to assets that were bridged from Axelar to Secret through IBC. Other IBC connections or Secret tokens did not appear to be affected, and other Axelar integrations were not affected.

Axelar also stated that its core protocol was not affected. In its description, the affected area was not Axelar’s core protocol itself, but a specific smart-contract component on the Secret side of the IBC connection between Secret and Axelar. The statement separated the affected bridged assets and connections from the parts that Axelar said remained unaffected.

Common Prefix says attacker used an infinite mint vulnerability

Separately, according to Common Prefix’s analysis of the Secret Network incident, an attacker exploited an infinite mint vulnerability in a modified CW20-ICS20 token contract on Secret and stole about $4.67 million. The attacker launched a new Cosmos chain with only one validator and self-relayed IBC packets to it as part of the attack process.

Common Prefix said this allowed the attacker to mint arbitrary Secret-wrapped Axelar assets on Secret. The contract did not verify which IBC channel inbound tokens came from. The attacker then exited through the Axelar bridge. Common Prefix’s analysis also said the Axelar protocol was not compromised and that contagion to other chains was prevented.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.