RIADeFi

Axelar–Secret IBC route contained after unbacked-token drain

The Ledger · · Ketju Research

ContainedMixed evidence

Developing. Some claims here are not yet confirmed; they are listed apart from the confirmed facts. A new version replaces this one when the primary evidence changes.

Affects: Axelar (protocol)

What happened

An attacker exploited the Secret-side ICS-20 contract used by the Axelar–Secret route, minted unbacked saTokens, and redeemed them through the legitimate channel against real escrowed assets.

What changed

The affected saTokens became impaired or undercollateralized, and the Axelar Secret and Secret-SNIP connections were paused after discovery.

What did not change

The primary account says Axelar's core validator and threshold-signature protocol and other Axelar integrations were not affected; containment does not imply asset recovery.

Confirmed

  • The exploit occurred on June 10, 2026 and involved the Secret-side contract at secret1yxjmepvyl2c25vnt53cr2dpn8amknwausxee83.
  • The official account estimates approximately $4.67 million of unbacked tokens were minted and redeemed against genuine bridge reserves.
  • Axelar–Secret bridging was disabled and the relevant connections were paused by June 19.
  • Existing Axelar-bridged saTokens on Secret were identified as impaired or undercollateralized.

Still open

  • Axelar and Secret accounts differ on responsibility for monitoring and recovery decisions; this draft does not resolve that dispute.
  • The amount ultimately recoverable and the disposition of residual attacker-controlled funds remain unresolved.

What it means for an advisor

  • Treat the Axelar–Secret route and its saTokens as unavailable pending verified recapitalization and restoration.
  • Review every approved use of Axelar at the receiving-contract level; Axelar core approval does not validate a downstream integration's source authentication.
  • Reopen the Axelar memo to record the integration-layer loss and containment without misclassifying it as a core Axelar consensus compromise.

Sources

  1. Security Incident: Axelar<>Secret IBC Bridge Exploit (June 10, 2026) · Secret Network · · effective

Version 1, published . We check this event again on . Educational research, not investment advice.