- Attacker exploited a missing channel-verification check to mint $4.67M in fake tokens.
- Axelar disabled Secret Network connections after detecting the breach on June 17.
- Stolen funds moved through Osmosis and Ethereum before landing on three exchanges.
- Bridge exploits have drained over $340 million across crypto so far this year.
A vulnerability that has sat unnoticed in a Secret Network smart contract since 2023 cost users $4.67 million this month, the latest reminder that cross-chain bridges remain crypto’s most exploited attack surface.
The exploit targeted the IBC connection linking Axelar and Secret Network, two interoperable Cosmos chains. On June 10, an attacker discovered that the contract governing transfers between the two networks never checked which channel an incoming deposit actually arrived through; it only matched the token’s name against an approved list.
That gap allowed the attacker to spin up an independent chain with a single validator, open an unauthorized channel into the Secret-side contract, and self-relay forged deposits that minted real, redeemable saTokens with no backing.
How the Laundering Trail Unfolded
Once minted, the attacker redeemed the fake saUSDT, saUSDC, and five other wrapped assets through the legitimate Axelar channel, draining the genuine reserves held in escrow.
Proceeds were routed through Osmosis to Ethereum, where they were swapped for ETH via CoW Protocol, split across roughly 30 wallets, and funneled into KuCoin, ChangeNow, and HitBTC.
Axelar said it caught the discrepancy on June 17, nine days after the attack, when a routine cross-chain transfer failed because the escrow account no longer held enough tokens to cover it.
Investigators traced the shortfall to seven anomalous transactions from June 10 and disabled the Secret connection within hours. The company maintains that its core protocol and other integrations were unaffected, with damage confined to assets specifically wrapped for the Secret-Axelar route.
A Familiar Weak Point
The incident extends a costly pattern. Bridges built on similar lock-and-mint logic have lost more than $340 million to comparable flaws this year, including Resolv’s $25 million breach, Verus’ $11 million loss, and a $4 million hit to IoTeX.
In each case, attackers found gaps in the checks meant to confirm that minted tokens were genuinely backed by locked collateral.
Despite the breach, the market reaction has been mild. Axelar (AXL) coin slipped just 2.2% on the day, per CoinMarketCap, while Secret (SCRT) held steady, down less than 1%. That’s a softer response than past bridge hacks have triggered, suggesting traders are, for now, taking Axelar’s “core protocol unaffected” claim at face value.
Axelar says it is coordinating with exchanges and law enforcement to trace the stolen funds and is preparing a full post-mortem. No timeline has been given for restoring the Secret connection.
READ MORE: Why is the Crypto Market Crashing as US Indices Like Nasdaq 100, S&P 500 Surge?