Incident case

Axelar–Secret IBC Bridge 2026 source-channel validation exploit

On June 10, 2026, the Secret-side ics20-for-axelar contract accepted inbound cross-chain token messages without authenticating the expected source IBC channel. An attacker used that verification gap to mint unbacked Axelar-wrapped assets on Secret and redeem them through the legitimate Axelar connection against real reserves. Secret reported approximately USD 4.67 million stolen. The connection was disabled, no returned attacker funds are established in the admitted record, and a later Axelar governance vote only signaled a non-binding future freeze/recustody and victim-distribution path.

reviewedcurrent

Incident facts

Incident title
Axelar–Secret IBC Bridge 2026 source-channel validation exploit
Bridge
Axelar–Secret IBC Bridge
Incident date
2026-06-10
Incident type
Exploit
Major incident
Yes
Affected chains
Secret Network, Axelar
Affected assets
USDT, USDC, WETH, WBTC, DAI, WBNB, wstETH
Attack category
Message Verification Failure
Reported loss
about USD 4.67 million
Amount confidence
High
Loss amount basis
Reported By Project
Recovery
None
Reimbursement
Announced
Restart
Not Reopened
Current outcome
Paused Long Term
Postmortem
Available
Resolution
Unresolved
Last reviewed
2026-08-21
Last verified
2026-08-21

Amount and valuation

Secret Network's first-party incident report states that approximately USD 4.67 million of genuine Axelar-side reserves were drained after unbacked Axelar-wrapped assets were minted on Secret and redeemed through the legitimate bridge path.

Use the first-party approximate aggregate. Identifiable attacker-held assets, changing market valuations, potential future freezes and victim-distribution proposals are separate from the incident loss and are not subtracted from this amount.

Why this remains unresolved

Timeline events

  • Axelar–Secret bridge connection disabled after discovery2026-06

    After the June exploit was discovered, Secret disabled bridging through Secret Tunnel and Axelar paused the Secret and Secret-SNIP connections. The service remains non-operational at the latest review.

    Bridge PausedHigh

    Month precision avoids inventing a single exact disable timestamp from a multi-step discovery and containment sequence.

  • Unbacked Axelar-wrapped assets minted and redeemed2026-06-10

    The Secret-side bridge contract accepted token messages without authenticating the legitimate source IBC channel. Unbacked Axelar-wrapped assets were minted on Secret and redeemed through the valid Axelar connection against real reserves, producing an approximately USD 4.67 million loss.

    Exploit OccurredHigh

    Public mechanism description intentionally stops at the missing source-channel authentication boundary and omits exploit reproduction steps.

  • Axelar governance signals future hacker-fund recustody and victim distribution2026-07-05

    Axelar governance Proposal #490 passed as an explicitly non-binding signaling proposal supporting a future process to freeze identified hacker funds and later recustody them to a trusted distributor for affected users.

    Reimbursement AnnouncedHigh

    The proposal itself does not move, freeze, seize, recustody or distribute funds and is not a recovery-completion event.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.