Incident case file
Sign in to watchAxelar-Secret Network ICS-20 Bridge Infinite-Mint Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — not visible on-chain (Secret Network transactions and balances are encrypted by design). The attacker reportedly launched an independent single-validator Cosmos chain to self-relay unauthorized IBC deposits (per Common Prefix forensic analysis).
Timeline: Forensic analysis by Common Prefix indicates the actual exploit was executed on June 10, 2026, though it was not publicly disclosed until June 19, 2026. An attacker exploited an infinite-mint bug in a modified CW20-ICS20 token contract deployed on Secret Network, used in the Cosmos IBC bridge connection with Axelar. The Secret-side ICS-20 contract failed to properly verify the originating IBC channel of incoming deposits, instead matching only the token denomination against an allowlist — allowing the attacker to mint real, redeemable Axelar-wrapped assets without a corresponding legitimate deposit. According to Common Prefix's analysis, the attacker accomplished this by launching an independent single-validator Cosmos chain, which allowed them to open an unauthorized IBC channel and self-relay falsified deposit packets. The exploit drained approximately $4.67M in bridged assets. On June 19, 2026, Axelar Network publicly disclosed the incident on X, stating the issue was 'isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection' and confirming the core Axelar protocol was not compromised. Axelar's emergency committee immediately disabled the Secret and Secret-SNIP IBC connections. Security researcher group F12 published the affected contract addresses the same day. Laundering analysis traced the proceeds moving from Osmosis to Ethereum, swapped to ETH via CoW Protocol, and distributed across approximately 30 wallets before being deposited into KuCoin, ChangeNow, and HitBTC. Because Secret Network transactions and balances are encrypted by design, the attacker's identity and on-chain address remain unrecoverable through public block explorers. Axelar has coordinated with exchanges and law enforcement; a full post-mortem is pending.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)