← Radar

Incident case file

Sign in to watch

Axelar-Secret Network ICS-20 Bridge Infinite-Mint Exploit

Incident date June 19, 2026

1 views

ContainedSecret NetworkCosmos IBCBridge exploit — infinite-mint bug in modified CW20-ICS20 contractCluster: AXL-SCRT-2026-06

Estimated loss

$4.7M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: MISSING — not visible on-chain (Secret Network transactions and balances are encrypted by design). The attacker reportedly launched an independent single-validator Cosmos chain to self-relay unauthorized IBC deposits (per Common Prefix forensic analysis).

Funds moved to: ~$4.67M drained via an infinite-mint exploit on Secret-side ICS-20 contracts. Laundering path: Osmosis to Ethereum, swapped to ETH via CoW Protocol, distributed across ~30 wallets, then deposited to KuCoin, ChangeNow, and HitBTC.
Victim contracts (Secret Network): secret1yxjmepvyl2c25vnt53cr2dpn8amknwausxee83 (primary), secret1nvytjz7t5wakf0ra5y47dfenatwxpggmkwc5ru, secret1e2lwttdwnpxpg6hudplfl54pdx4404nm54mj8r. IMPORTANT DATE CAVEAT: forensic analysis indicates the actual exploit execution occurred on June 10, 2026, though public disclosure, IBC connection shutdown, and laundering-trail analysis all occurred on June 19, 2026 — within this reporting window. Consider whether the radar's date convention should reflect th

Timeline: Forensic analysis by Common Prefix indicates the actual exploit was executed on June 10, 2026, though it was not publicly disclosed until June 19, 2026. An attacker exploited an infinite-mint bug in a modified CW20-ICS20 token contract deployed on Secret Network, used in the Cosmos IBC bridge connection with Axelar. The Secret-side ICS-20 contract failed to properly verify the originating IBC channel of incoming deposits, instead matching only the token denomination against an allowlist — allowing the attacker to mint real, redeemable Axelar-wrapped assets without a corresponding legitimate deposit. According to Common Prefix's analysis, the attacker accomplished this by launching an independent single-validator Cosmos chain, which allowed them to open an unauthorized IBC channel and self-relay falsified deposit packets. The exploit drained approximately $4.67M in bridged assets. On June 19, 2026, Axelar Network publicly disclosed the incident on X, stating the issue was 'isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection' and confirming the core Axelar protocol was not compromised. Axelar's emergency committee immediately disabled the Secret and Secret-SNIP IBC connections. Security researcher group F12 published the affected contract addresses the same day. Laundering analysis traced the proceeds moving from Osmosis to Ethereum, swapped to ETH via CoW Protocol, and distributed across approximately 30 wallets before being deposited into KuCoin, ChangeNow, and HitBTC. Because Secret Network transactions and balances are encrypted by design, the attacker's identity and on-chain address remain unrecoverable through public block explorers. Axelar has coordinated with exchanges and law enforcement; a full post-mortem is pending.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)