Skip to main content
Sign in

Secret Network / Axelar Bridge Exploit June 2026

avoid.net/secret-network-axelar-bridge-exploit-june-20268/100·87% conf.
[AI-DRAFTED · AWAITING VERIFICATION]
anchored·29ZFau…PxRG

Summary

On June 10, 2026, an attacker exploited a missing channel-origin validation in a customized CW20-ICS20 smart contract on Secret Network to mint approximately $4.67 million in unbacked Axelar-wrapped tokens (saTokens) and redeem them for real escrowed assets. The exploit went undetected for seven days due in part to Secret Network's privacy-by-default architecture, which encrypts account balances and masked the missing collateral until a failed cross-chain transfer on June 17 exposed the shortfall. Blockchain security firm Common Prefix traced the vulnerability to the contract's initial deployment in early 2023; a March 5, 2026 contract migration added new functionality but carried the unpatched validation flaw forward without a new security audit.

Have evidence about Secret Network / Axelar Bridge Exploit June 2026?

Timeline(7 events)

2023-03-01

Vulnerable CW20-ICS20 bridge contract originally deployed on Secret Network without the parse_voucher_denom() and reduce_channel_balance() validation checks. No external security audit was requested.

Common Prefix postmortem (via CryptoTimes and yellow.com)

2026-03-05

Contract migrated to Code ID 2446 to add new functionality. The migration preserved the missing source-validation checks without remediation and without triggering a new security audit.

CryptoTimes / Common Prefix postmortem

2026-06-10

Attacker creates a single-validator Cosmos chain, opens an unauthorized IBC channel to the vulnerable bridge contract, self-relays forged packets, and mints approximately $4.67 million in unbacked saTokens across seven asset classes before redeeming them for real escrowed assets.

CryptoTimes, The Block, CryptoWisser

2026-06-17

A legitimate cross-chain transfer from a normal user fails due to insufficient escrow reserves, exposing the shortfall. Investigators trace the deficit to the seven withdrawals executed on June 10. Secret Network's encrypted balances had masked the missing collateral for seven days.

CryptoWisser, CryptoTimes, BanklessTimes

2026-06-19

Axelar's emergency committee disables the Secret and Secret-SNIP IBC connections (channels 60/61). Squid router removes Secret Network from its interface. Axelar and Secret Network make initial public disclosures.

CryptoTimes, KuCoin, The Block

2026-06-20

CryptoTimes publishes technical post-mortem detailing the two missing validation functions, the March 2026 migration history, and the attacker's methodology. Yellow.com and BanklessTimes publish additional analysis attributing the postmortem to blockchain security firm Common Prefix.

CryptoTimes, yellow.com, BanklessTimes

2026-06-22

Cointelegraph and additional outlets publish coverage. SCRT reported down approximately 28.5% for the month. Axelar formally clarifies that its core protocol was not breached and that the exploited contract was not its responsibility. No compensation plan or bridge restoration timeline announced.

CoinTelegraph via TradingView, KuCoin, CryptoWisser
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-sonnet-4-6

generated: 6/30/2026, 5:09:32 PM

last updated: 6/30/2026, 5:09:41 PM

avoid.net — verified advice for a post-truth world