Axelar Separates the Incident From Its Own Network and IBC
Axelar Network issued a statement addressing the recent security incident related to Secret Network, saying there has been a misunderstanding in the community about what was affected. The cross-chain protocol stated that Axelar Network itself and the Inter-Blockchain Communication Protocol, or IBC, were not attacked or compromised. Axelar also said the affected token smart contract was not developed, deployed, or maintained by Axelar.
In its explanation, Axelar drew a clear line between its own cross-chain infrastructure, the IBC protocol, and the third-party contract involved in the incident. The team said Axelar’s firewall mechanism also prevented the impact from spreading further to other chains. This was presented as part of its response to claims or assumptions that the incident involved Axelar or IBC directly.
The Flaw Came From a Modified CW20-ICS20 Fork
According to Axelar Network, the exploited contract was a forked version based on a CW20-ICS20 implementation. The developer of that fork removed two core security checks, which led to an “infinite mint” vulnerability. Axelar said those checks originally existed to prevent this type of issue, and their removal changed the original trust model of the contract.
Axelar also stated that the modified fork did not undergo a new security audit after the key safety checks were removed. In Axelar’s account, the incident was not described as a unique logic flaw in the original implementation, nor as a failure of the IBC protocol itself. Instead, the risk was introduced when a third-party contract was altered in a way that removed safeguards and changed its security assumptions.
The network further explained that anyone can deploy contracts through IBC for wrapping cross-chain assets, and similar contracts have also been used to wrap tokens from other chains onto Secret Network. In this specific case, Axelar said the Secret-side fork contained the vulnerability because it had deleted critical safety checks. The incident, according to Axelar, came from third-party contract modifications rather than from Axelar, IBC, or a protocol-level flaw.

