Axelar–Secret IBC Bridge 2026 source-channel validation exploit
On June 10, 2026, the Secret-side ics20-for-axelar contract accepted inbound cross-chain token messages without authenticating the expected source IBC channel. An attacker used that verification gap to mint unbacked Axelar-wrapped assets on Secret and redeem them through the legitimate Axelar connection against real reserves. Secret reported approximately USD 4.67 million stolen. The connection was disabled, no returned attacker funds are established in the admitted record, and a later Axelar governance vote only signaled a non-binding future freeze/recustody and victim-distribution path.
Incident facts
- Incident title
- Axelar–Secret IBC Bridge 2026 source-channel validation exploit
- Bridge
- Axelar–Secret IBC Bridge
- Incident date
- 2026-06-10
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Secret Network, Axelar
- Affected assets
- USDT, USDC, WETH, WBTC, DAI, WBNB, wstETH
- Attack category
- Message Verification Failure
- Reported loss
- about USD 4.67 million
- Amount confidence
- High
- Loss amount basis
- Reported By Project
- Recovery
- None
- Reimbursement
- Announced
- Restart
- Not Reopened
- Current outcome
- Paused Long Term
- Postmortem
- Available
- Resolution
- Unresolved
- Last reviewed
- 2026-08-21
- Last verified
- 2026-08-21
Amount and valuation
Secret Network's first-party incident report states that approximately USD 4.67 million of genuine Axelar-side reserves were drained after unbacked Axelar-wrapped assets were minted on Secret and redeemed through the legitimate bridge path.
Use the first-party approximate aggregate. Identifiable attacker-held assets, changing market valuations, potential future freezes and victim-distribution proposals are separate from the incident loss and are not subtracted from this amount.
unbacked saUSDT, saUSDC, saWETH, saWBTC, saDAI, saWBNB and sawstETH redeemed against genuine reservesabout USD 4.67 million
Canonical aggregate from Secret Network's first-party incident report.
Why this remains unresolved
- No admitted source establishes return, freeze execution, recustody, or protocol control of the remaining attacker-held assets.
- Axelar Proposal #490 passed only as a non-binding signaling proposal and did not itself move, freeze, seize, recustody, or distribute funds.
- Final affected-user reimbursement amount and completion are not established.
- Secret Tunnel remains non-operational due to the security incident and no bridge reopening is established.
Timeline events
Axelar–Secret bridge connection disabled after discovery2026-06
After the June exploit was discovered, Secret disabled bridging through Secret Tunnel and Axelar paused the Secret and Secret-SNIP connections. The service remains non-operational at the latest review.
Month precision avoids inventing a single exact disable timestamp from a multi-step discovery and containment sequence.
Unbacked Axelar-wrapped assets minted and redeemed2026-06-10
The Secret-side bridge contract accepted token messages without authenticating the legitimate source IBC channel. Unbacked Axelar-wrapped assets were minted on Secret and redeemed through the valid Axelar connection against real reserves, producing an approximately USD 4.67 million loss.
Public mechanism description intentionally stops at the missing source-channel authentication boundary and omits exploit reproduction steps.
Axelar governance signals future hacker-fund recustody and victim distribution2026-07-05
Axelar governance Proposal #490 passed as an explicitly non-binding signaling proposal supporting a future process to freeze identified hacker funds and later recustody them to a trusted distributor for affected users.
The proposal itself does not move, freeze, seize, recustody or distribute funds and is not a recovery-completion event.
Evidence records
- Security Incident: Axelar<>Secret IBC Bridge Exploit — June 10, 2026Secret Network · Tier 1 · High reliability · primary · 2026-06-19Claim scope: Incident Case
Core first-party incident authority for exploit date, source-channel validation defect, affected assets, approximately USD 4.67M loss, containment, attacker-held residual and unaffected-system boundary.
- The Secret Network ExploitCommon Prefix · Tier 2 · High reliability · secondary · 2026-06-19Claim scope: Incident Case
Independent technical reconstruction corroborating the Secret-side contract failure and loss scope. Public BIR prose remains non-operational.
- Secret Network's Axelar bridge drained for $4.67 million in exploitThe Block · Tier 2 · High reliability · secondary · 2026-06-20Claim scope: Amount
Independent contemporaneous corroboration for amount, detection/containment context and the boundary that Axelar core was not compromised.
- Security Incident: Axelar<>Secret IBC Bridge Exploit — June 10, 2026Secret Network · Tier 1 · High reliability · primary · 2026-06-19Claim scope: Shutdown
Event-scoped primary copy supporting disabling Secret bridging and pausing Axelar Secret / Secret-SNIP connections after discovery.
- Secret TunnelSecret Network · Tier 1 · High reliability · primary · 2026Claim scope: Status
Current first-party service state reviewed 2026-08-21: Secret Tunnel states it is not operational due to a security incident. Year precision avoids inventing a publication date for the live status page.
- Axelar governance Proposal #490Axelar governance · Tier 1 · High reliability · primary · 2026-07-05Claim scope: Reimbursement
Direct governance proposal record. Proposal #490 passed as explicitly non-binding signaling for a future hacker-fund freeze/recustody and victim-distribution path; it does not itself execute those actions.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The final disposition of attacker-held assets remains unresolved.
- No binding execution of the governance-signaled freeze/recustody/distribution path was located at review time.
- BIR does not infer impact to Axelar core, IBC generally, Secret consensus/privacy, native SCRT, unrelated SNIP-20 assets, Noble USDC or other bridge connections.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.