Axelar disables Secret IBC connections following a $4.67M exploit on Secret's ICS-20 contract.
Security & Exploits ·
Axelar Network identified an exploit affecting assets bridged to Secret Network through its IBC connection, resulting in approximately $4.67M in token losses. Upon discovery, Axelar's emergency committee disabled the Secret and Secret-SNIP connections, and the network is coordinating with exchanges and law enforcement. The incident was contained to assets on Secret's side of the bridge; no other IBC connections, Axelar integrations, or Axelar's core protocol were affected.
Analysis revealed an attacker exploited an infinite-mint vulnerability in a modified CW20-ICS20 token contract on Secret. The attacker created a new Cosmos chain with a single validator and used self-relayed IBC packets to mint arbitrary Secret-wrapped Axelar assets, exploiting the contract's failure to validate the source of inbound tokens. The malicious actor then exited through the Axelar bridge. Axelar's firewalling prevented contagion to other chains.
The vulnerability stemmed from a fork of the CW20-ICS20 contract that had two core security checks commented out, introducing the infinite-mint bug. Neither Axelar nor IBC itself was compromised; the issue lay solely in the modified smart contract, which underwent no new audit after its trust model changed. Axelar is preparing a detailed post-mortem, though details on remediation timing and broader recovery plans remain unclear.