En.Bloomingbit Axelar Bridge Exploit Results in $4.67 Million Loss Linked to Secret Network
Article Content
- •Approximately $4.67 million in tokens were drained from the Secret Network due to a contract exploit.
- •The exploit targeted a modified ICS-20 smart contract, failing to verify token transfer origins.
- •Axelar's core protocol and other IBC connections were not affected, and an investigation is ongoing.
On June 19, 2026, Axelar Network reported a security incident where approximately $4.67 million worth of tokens were drained from the Secret Network due to an exploit in a modified ICS-20 smart contract. The attacker exploited vulnerabilities in the contract that failed to verify token transfers from an authentic Axelar-controlled IBC channel. This incident specifically affected bridged assets from Axelar to Secret Network, including wrapped USDT, USDC, DAI, WETH, WBTC, WBNB, and wstETH. Axelar's core protocol and other IBC connections remained unaffected. In response, Axelar disabled the affected bridge connections and initiated an investigation while contacting law enforcement and exchanges. The vulnerability was traced back to a lack of critical security checks in the contract, which allowed for the creation of unbacked wrapped tokens. A full post-mortem is expected to provide further insights into the incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (19)
Following this threat?
Track Axelar Network in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…