Secret Network – Axelar IBC bridge hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 19, 2026 |
| Target type | Cross-chain bridge |
| Loss | $4,670,000Price at time of incident |
| Method | Contract logic errorSecret Network's ics20-for-axelar contract was a customised fork of CW20-ICS20 in which two validation routines had been commented out: parse_voucher_denom, which validates the denomination trace against the packet's source channel, and reduce_channel_balance, which caps releases at the amount actually escrowed for that channel. The contract therefore minted whenever an incoming denomination matched its allowlist, regardless of which IBC channel the packet arrived on. Because IBC channel opening is permissionless, the attacker stood up a chain under their own control, opened a channel to the bridge contract and sent seven forged deposit packets, minting unbacked saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB and sawstETH, then redeemed them through the genuine Axelar channel to drain the real reserves. |
| Chains | Other, Ethereum |
| Outcome | Unresolved |
What happened
Secret Network's bridge to Axelar ran a customised fork of the CW20-ICS20 contract, which mints wrapped tokens on Secret when a matching IBC transfer arrives. In the fork, two checks present in the upstream code had been commented out: the routine that validates the voucher denomination against the packet's source channel, and the routine that caps releases at the amount actually escrowed for that channel. The contract therefore minted whenever an incoming denomination matched its allowlist, regardless of which channel the packet came from. Common Prefix traced the missing checks to the repository's first commit in January 2023, and the flawed code survived a migration in March 2026. The contract was an unaudited fork.
Because IBC channel opening is permissionless, on 10 June 2026 an attacker stood up a chain under their own control, opened a channel to the bridge contract and sent seven forged deposit packets. The contract minted unbacked saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB and sawstETH, and the attacker redeemed them back through the genuine Axelar channel within about 18 minutes, draining the real reserves held on the Axelar side.
Secret Network says Axelar notified it on 17 June 2026, after which the Axelar emergency committee disabled the Secret and Secret-SNIP connections and bridging was switched off on the Secret tunnel front end. Both parties put the loss at about $4.67 million. The proceeds moved through Osmosis to Ethereum and BNB Chain, were consolidated into roughly 2,349 ETH, split across about 30 addresses, and cashed out mainly through ChangeNOW and KuCoin. About $770,000 remained in the attacker's Axelar wallet, which Secret says Axelar declined to freeze. Secret's core protocol, native SCRT and other IBC routes were unaffected.
Law enforcement
Secret Network says it engaged law enforcement and exchanges with full transaction documentation. No public case, charge or seizure has been identified.
Sources
- Secret NetworkPrimary · retrieved 2026-08-01
- Common PrefixSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
Official post-mortem: https://forum.scrt.network/t/security-incident-axelar-secret-ibc-bridge-exploit-june-10-2026/7995
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Secret Network – Axelar IBC bridge hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/secret-network-axelar-bridgehttps://itokenly.com/hacks/secret-network-axelar-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.