Hacker Drained $4.67M From Secret Network's Axelar Bridge Using Fake IBC Channel on June 10

WAXL-0.30%
ATOM-0.67%
OSMO-1.59%
ETH-0.58%
COW1.96%

An attacker exploited a missing channel validation flaw in Secret Network's modified CW20-ICS20 bridge contract to drain roughly $4.67 million on June 10. The exploit went undetected until June 17, when a cross-chain transfer failed due to depleted escrow assets. The attacker used a single-validator Cosmos chain to forge deposits and mint Secret-wrapped tokens without real assets backing them, affecting seven tokens including saUSDT, saUSDC, and saDAI.

The vulnerability existed since the contract's initial deployment in early 2023 and was not addressed in a March 5 migration. Secret Network attributed the delayed detection to encrypted balances on the network, which prevented visible monitoring of missing collateral. The stolen funds were moved to Axelar, routed through Osmosis to Ethereum, and swapped for ether via CoW Protocol before being split into deposits at KuCoin, ChangeNow, and HitBTC. Approximately $672,000 remained in the attacker's Axelar wallet. Axelar's emergency committee disabled the affected connections and said its core protocol was not compromised.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments