ChainCatcher reported that blockchain research firm Common Prefix disclosed an exploit involving the Secret Network and Axelar cross-chain bridge. According to the disclosure, an attacker used a contract vulnerability on June 10 to forge deposits, mint tokens without collateral backing and then exchange the assets for approximately $4.67 million. The incident was not identified on the day it occurred. Instead, the attack remained unnoticed for seven days before the abnormal activity came to light.
Normal transfer failure exposed the issue after seven days
Common Prefix said the problem was discovered on June 17, when a normal cross-chain transfer failed because the custody account did not have enough funds. That failed transfer revealed that the account balance no longer matched the expected state. Between June 10 and June 17, the forged deposits and token minting activity had already taken place, and the funds had moved into the next stage of routing and conversion.
The root cause, according to the disclosure, was tied to a contract change from a custody model to a minting model. During that change, two key functions responsible for verifying the source of transfers were removed. Common Prefix also stated that the contract had not undergone an external audit since it was deployed in early 2023. Without those source-verification functions, the attacker was able to create fake deposits and mint tokens that were not backed by corresponding collateral.
Funds routed through Osmosis, Ethereum and exchanges
Secret Network said Axelar’s bridge infrastructure did not trigger any effective anomaly monitoring or emergency pause mechanism before a large amount of assets was stolen. The stolen funds were routed through Osmosis to Ethereum, converted into ETH on CoW Protocol, and then distributed to exchanges including KuCoin, ChangeNow and HitBTC. Around $672,000 remains in the attacker’s Axelar wallet at present.
Secret Network has asked Axelar to freeze that address, but the request was rejected. Axelar emphasized that its core protocol was never affected and said the exploited contract was not developed or maintained by Axelar. Axelar has disabled the related cross-chain connection and said it is coordinating with exchanges and law enforcement agencies on the matter.

