πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
Blockchain

Secret Network's Axelar Bridge Hit by a $4.67M Infinite Mint

17 Jun 2026by CryptoJazz Admin1 min read4 views
Secret Network's Axelar Bridge Hit by a $4.67M Infinite Mint

Secret Network lost roughly $4.67 million in bridged assets to an infinite-mint exploit on its Axelar connection, an attack that ran on June 10 and was only identified a week later, on June 17. The attacker created tokens on Secret that no deposit backed, then redeemed them for real assets over the legitimate Axelar route. Axelar found the problem while investigating a routine transfer failure and disabled the Secret connection within hours of confirming it. Seven wrapped assets were affected: saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB and sawstETH. The core Axelar protocol was unaffected, according to the disclosure, and the cross-chain router Squid removed Secret from its interface.

The Flaw: An Allow-List Where an Escrow Check Belonged

The failure sat in a customized version of CW20-ICS20, the contract that converts tokens arriving over IBC, the messaging standard Cosmos chains use to move assets between one another, into their wrapped form on the destination chain. The customized contract did not verify the source channel a packet claimed to come from, and it did not check that the escrow holding the underlying deposit actually contained the assets being credited. Instead it matched incoming transfers against an allow-list of denominations. Anything whose denomination string looked correct was treated as a legitimate inbound transfer and minted, regardless of where the packet originated or whether anything backed it. The loss was attributed to that customization rather than to the standard the contract was derived from.

The Attack: A One-Validator Chain Built to Forge Packets

Exploiting that gap required somewhere to send packets from, so the attacker built one. They launched a fake Cosmos chain secured by a single validator they controlled, opened a fresh IBC channel from it to Secret, and relayed forged transfer packets across it. The customized contract read the denominations, found them on its allow-list and minted unbacked saTokens against deposits that never existed. The attacker then redeemed those tokens through the real Axelar route, channel-69 on the Axelar side and channel-61 on the Secret side, converting synthetic balances into assets other users had actually deposited. It was the second bridge failure in June in which a bridge bug minted tokens with nothing behind them, after the roughly 5 billion SYS created through a cross-layer mismatch in Syscoin's bridge on June 7.

The Response: Connection Disabled, Routing Withdrawn

Axelar's detection path is worth noting because nothing in the mint itself raised an alarm. The forged transfers looked valid to the contract that processed them, and the discrepancy only surfaced when a transfer failed and engineers traced why the escrow balances did not reconcile. Once confirmed, Axelar disabled the Secret connection, which stopped further redemptions but did not reverse the ones already settled. Squid, which routes swaps across Axelar, removed Secret from its interface, cutting off the most common consumer path into the affected assets. No recovery of the drained funds had been disclosed as of June 17.

What Is Unresolved: The Cost of Forking a Standard Contract

The narrow question is what happens to holders of the seven affected saTokens, whose backing is now short by the amount minted, and whether Secret restores the Axelar route with an audited contract or rebuilds it. The broader one is how many other deployments run modified copies of standard IBC contracts with verification steps quietly dropped during customization. This was a failure of code that had been changed, not of the standard it was derived from, and the same pattern is difficult to find from the outside because the contract still behaves normally under honest traffic. It also lands in a month whose other large losses came from custody failures rather than contract logic, including Humanity Protocol's drain on June 9 after multisig keys intended for four separate people were backed up to a single compromised laptop. Different root causes, the same outcome: assets moved by someone who should never have been able to authorize the move.

Read also: Taiko Halts Its Ethereum Layer-2 After a $1.7M Bridge Exploit

← All news