Axelar Bridge Exploit Results in $4.67 Million Loss Linked to Secret Network

Axelar Bridge Exploit Results in $4.67 Million Loss Linked to Secret Network

First seen 20 Jun 2026, 09:23 UTC ValuethemarketsBitgetEn.BloomingbitKucoinCryptopolitan+7 87% similarity 66.0

Article Content

Browse articles
ThreatCluster

On June 19, 2026, Axelar Network reported a security incident where approximately $4.67 million worth of tokens were drained from the Secret Network due to an exploit in a modified ICS-20 smart contract. The attacker exploited vulnerabilities in the contract that failed to verify token transfers from an authentic Axelar-controlled IBC channel. This incident specifically affected bridged assets from Axelar to Secret Network, including wrapped USDT, USDC, DAI, WETH, WBTC, WBNB, and wstETH. Axelar's core protocol and other IBC connections remained unaffected. In response, Axelar disabled the affected bridge connections and initiated an investigation while contacting law enforcement and exchanges. The vulnerability was traced back to a lack of critical security checks in the contract, which allowed for the creation of unbacked wrapped tokens. A full post-mortem is expected to provide further insights into the incident.

Key Points: • Approximately $4.67 million in tokens were drained from the Secret Network due to a contract exploit. • The exploit targeted a modified ICS-20 smart contract, failing to verify token transfer origins. • Axelar's core protocol and other IBC connections were not affected, and an investigation is ongoing.

ThreatCluster AI How this analysis works

Timeline

2026-06-19
Security incident reported by Axelar
Axelar disclosed a loss of approximately $4.67 million due to an exploit in a Secret Network contract.
Cryptopolitan
2026-06-19
Axelar disables Secret Network bridge connections
Following the exploit, Axelar shut down connections to prevent further losses and initiated an investigation.
Bitget
2026-06-20
Axelar confirms core protocol unaffected
Axelar stated that its core protocol and other IBC connections remain secure and operational despite the incident.
Kucoin
2026-06-20
Investigation into the exploit initiated
Axelar's emergency committee began investigating the exploit's details and the extent of the losses.
Valuethemarkets
2026-06-20
Vulnerability traced to third-party contract
Axelar clarified that the exploit was due to a vulnerability in a forked version of the ICS-20 contract, not in its core protocol.
Weex

Community

Browse all →