ChainCatcher reported that blockchain research organization Common Prefix disclosed an exploit involving a cross-chain bridge contract connected to Secret Network and Axelar. According to the disclosure, a hacker used the vulnerability on June 10 to forge deposits and mint tokens without collateral, then exchanged the assets and cashed out approximately $4.67 million.
A failed routine transfer revealed the issue
The attack was not detected immediately. It remained unnoticed for seven days, until June 17, when a normal cross-chain transfer failed because the custodial account did not have enough funds. That failed transaction exposed the abnormal condition and led to the identification of the exploit.
Common Prefix attributed the root cause to changes made when the contract model was shifted from a custodial model to a minting model. During that change, two key functions responsible for verifying the origin of transfers were removed. The disclosure also stated that the contract had not undergone an external audit since it was deployed in early 2023.
Secret Network said Axelar’s bridge infrastructure did not trigger any effective anomaly monitoring or emergency pause mechanism before assets were stolen at scale. The disclosure presented the issue as a failure to stop the exploit before the attacker had already moved and converted a large amount of value.
Stolen funds moved through Osmosis, Ethereum and exchanges
The stolen funds were routed through Osmosis to Ethereum. They were then swapped into ETH on CoW Protocol and split across several exchanges, including KuCoin, ChangeNow and HitBTC. At present, about $672,000 remains in the attacker’s Axelar wallet.
Secret Network has asked Axelar to freeze that address, but the request was rejected. Axelar emphasized that its core protocol was never affected, and that the exploited contract was not developed or maintained by Axelar. Axelar has disabled the relevant cross-chain connection and said it is coordinating follow-up work with exchanges and law enforcement agencies.

