
A postmortem said the Secret-side flaw went undetected for seven days, traced back to 2023 code and later migrations, as Secret and Axelar disputed monitoring and recovery steps.
Axelar said about $4.67 million worth of bridged tokens were drained in a Secret Network incident caused by a third-party Secret Network CW20-ICS20 fork that removed two key security checks. A postmortem by Common Prefix said the flaw let an attacker use fake IBC packets from a single-validator Cosmos chain to mint unbacked Secret-wrapped Axelar assets and redeem them through Axelar’s normal mechanism, draining escrow across seven assets. The researcher said the bug dated to the contract’s initial deployment in early 2023 and was carried into a March 5 migration before the June 10 exploit, which was only detected on June 17 after a routine transfer failed. Axelar said it isolated the affected Secret route, that neither Axelar’s core protocol nor IBC itself was compromised, and that other chains, routes and escrow accounts were unaffected, while Secret said monitoring and freeze requests were not pursued.