Secret Network's Axelar Bridge Hit by a $4.67M Infinite Mint

Secret Network lost roughly $4.67 million in bridged assets to an infinite-mint exploit on its Axelar connection. The attack ran on June 10 and sat unnoticed for a week before Axelar engineers, tracing a routine transfer failure, found escrow balances that would not reconcile and identified it on June 17. Nobody caught it sooner. The attacker had minted tokens on Secret that no deposit backed, then redeemed them for real assets over the legitimate Axelar route, and Axelar disabled the Secret connection within hours of confirming what had happened. Seven wrapped assets were hit: saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB and sawstETH. The core Axelar protocol was untouched, the disclosure said, and the cross-chain router Squid pulled Secret from its interface.
An allow-list where an escrow check belonged
The failure sat in a customized version of CW20-ICS20, the contract that converts tokens arriving over IBC, the messaging standard Cosmos chains use to move assets between one another, into their wrapped form on the destination chain. The customized contract did not verify which source channel a packet claimed to come from. It also never checked that the escrow holding the underlying deposit actually contained the assets being credited. What it did instead was match incoming transfers against an allow-list of denominations. Anything whose denomination string looked right was treated as a legitimate inbound transfer and minted, no matter where the packet originated or whether anything backed it. The disclosure attributed the loss to that customization, not to the standard the contract was forked from.
A one-validator chain built to forge packets
Exploiting the gap required somewhere to send packets from. The attacker built one. They launched a fake Cosmos chain secured by a single validator they controlled, opened a fresh IBC channel from it to Secret, and relayed forged transfer packets across it. The customized contract read the denominations, found them on its allow-list and minted unbacked saTokens against deposits that never existed. The attacker then redeemed those tokens through the real Axelar route, channel-69 on the Axelar side and channel-61 on the Secret side, converting synthetic balances into assets other users had actually deposited. It was the second bridge failure of the month in which a bridge bug minted tokens with nothing behind them, after a cross-layer mismatch in Syscoin's bridge created roughly 5 billion SYS on June 7.
Detection came from a failed transfer, not the mint
Nothing in the mint itself raised an alarm. The forged transfers looked valid to the contract that processed them, and the discrepancy only surfaced when a transfer failed and engineers traced why the escrow did not add up. Once the exploit was confirmed, Axelar disabled the Secret connection, which stopped further redemptions but reversed none of the ones already settled. Squid, which routes swaps across Axelar, removed Secret from its interface, cutting off the most common consumer path into the affected assets. No recovery of the drained funds had been disclosed as of June 17.
The cost of forking a standard contract
The narrow question is what happens to holders of the seven affected saTokens, whose backing is now short by the amount minted, and whether Secret restores the Axelar route with an audited contract or rebuilds it. The broader one is how many other deployments run modified copies of standard IBC contracts with verification steps quietly dropped during customization. This was a failure of changed code, not of the standard behind it, and the same pattern is hard to spot from outside because the contract still behaves normally under honest traffic. It also lands in a month whose other large losses came from custody failures instead of contract logic, including Humanity Protocol's drain on June 9 after multisig keys meant for four separate people were backed up to a single compromised laptop. Different root causes, the same outcome. Assets moved by someone who should never have been able to authorize the move.
Read also: Taiko Halts Its Ethereum Layer-2 After a $1.7M Bridge Exploit