Axelar Network issued a clarification on the recent security incident connected to Secret Network, saying that parts of the community had misunderstood the nature of the event. According to Axelar, neither Axelar nor the Inter-Blockchain Communication Protocol, or IBC, was attacked or compromised. The affected token smart contract was not developed, deployed, or maintained by Axelar. The network also said its firewall mechanism prevented the impact from spreading further to other chains.
The exploited code came from a modified third-party fork
Axelar explained that the exploited contract was based on a forked version of the CW20-ICS20 implementation. In that fork, the developers removed two core safety checks. The removal of those checks introduced an “infinite mint” vulnerability, allowing the issue to arise from the altered contract implementation rather than from Axelar or IBC themselves.
The statement said the deleted validation logic had originally been designed to prevent this type of problem. Once those checks were removed, the trust model of the original contract was changed. Axelar also noted that the modified fork did not go through a new security audit after the changes were made. This distinction places the incident at the level of a third-party contract modification, rather than at the level of the cross-chain protocol or Axelar’s own maintained code.
Axelar separates IBC openness from the Secret-side contract flaw
Axelar further stated that anyone can deploy contracts through IBC for wrapping cross-chain assets. Similar types of contracts have also been used to wrap tokens from other chains onto Secret Network. In this case, the vulnerable component was the Secret-side forked version, which had removed key safety checks and therefore carried the flaw that was exploited.
The network emphasized that the incident was not a problem with the IBC protocol itself and was not the result of Axelar or IBC being breached. Its explanation centers on the modified CW20-ICS20 fork: a third-party version removed essential validation mechanisms, changed the original trust assumptions, and was not newly audited. Axelar said its firewall mechanism stopped the effect from extending to other chains.

