An attacker exploited a missing channel validation flaw in Secret Network's modified CW20-ICS20 bridge contract to drain roughly $4.67 million on June 10. The exploit went undetected until June 17, when a cross-chain transfer failed due to depleted escrow assets. The attacker used a single-validator Cosmos chain to forge deposits and mint Secret-wrapped tokens without real assets backing them, affecting seven tokens including saUSDT, saUSDC, and saDAI.
The vulnerability existed since the contract's initial deployment in early 2023 and was not addressed in a March 5 migration. Secret Network attributed the delayed detection to encrypted balances on the network, which prevented visible monitoring of missing collateral. The stolen funds were moved to Axelar, routed through Osmosis to Ethereum, and swapped for ether via CoW Protocol before being split into deposits at KuCoin, ChangeNow, and HitBTC. Approximately $672,000 remained in the attacker's Axelar wallet. Axelar's emergency committee disabled the affected connections and said its core protocol was not compromised.