According to Odaily, cross-chain protocol Axelar Network issued a clarification regarding a recent security incident connected to Secret Network, saying that parts of the community had misunderstood the nature of the event. Axelar stated that neither Axelar Network nor the Inter-Blockchain Communication Protocol (IBC) was attacked or compromised. The affected token smart contract, it said, was not developed, deployed, or maintained by Axelar.
Axelar also said its firewall mechanism prevented the impact from spreading further to other chains. In its explanation, the exploited contract was described as a forked version based on the CW20-ICS20 implementation. However, the developers of that fork removed two core security checks, which led to an “infinite mint” vulnerability.
According to Axelar Network, the removed validation mechanisms were originally intended to prevent this type of issue. By taking them out, the fork changed the original trust model of the contract, and the modified version did not undergo a new security audit. Axelar framed the incident as a risk introduced by changes made to a third-party contract, rather than a failure of Axelar’s own infrastructure.
The protocol further explained that anyone can deploy contracts through IBC for wrapping cross-chain assets. Similar contracts are also used to wrap tokens from other chains onto Secret Network. In this case, the Secret-side fork contained the vulnerability because key security checks had been removed. Axelar said the incident was not a unique logic flaw and was not a problem with the IBC protocol itself, but a security risk introduced after a third-party contract was modified.

