
A $4.67M exploit hit Axelar-bridged assets on Secret Network, forcing an emergency shutdown of affected IBC connections.
Author: Akshat Thakur
19th June 2026 – Axelar and Secret Network disclosed a bridge exploit on Friday. The Axelar Secret Network hack drained roughly $4.67 million.
High Signal Summary For A Quick Glance
Samurai Servo
@gridmanservo
@axelar Karma got you! During kelp hack you were more than happy to look down on $Zro. how does it feel now? lamo i am always amazed by people who wish bad for others. Hope u learn now
We have identified an incident affecting assets bridged over IBC to Secret Network from the Axelar chain, with approximately $4.67M worth of tokens taken. Based on current information, the issue is isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection
06:38 PM·Jun 19, 2026
SIRTRADESALOT
@COOLBREEZE_____
@axelar LMFAO WHO WOULD'VE THOUGHT 🤣🤣🤣🤣🤣😭😭😭😭😭😭😭😭😭😭 I SAW THIS COMING A MILE AWAY....SINCE YOU GUYS LAUNCHED..🤣😭
We have identified an incident affecting assets bridged over IBC to Secret Network from the Axelar chain, with approximately $4.67M worth of tokens taken. Based on current information, the issue is isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection
05:34 PM·Jun 19, 2026
2032.
@airball77
@axelar Why are you the last project on earth to not use chainlink and still get hit with a bridge exploit after 10 of these have already happened and all of those protocols switched to chainlink. It’s like you want to lose user funds or something I swear
We have identified an incident affecting assets bridged over IBC to Secret Network from the Axelar chain, with approximately $4.67M worth of tokens taken. Based on current information, the issue is isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection
02:53 PM·Jun 19, 2026
High attention and emotional sentiment detected.
Both teams shared near-identical statements at about 13:40 UTC. According to Axelar’s thread, the fault sits in the Secret-side ICS-20 contract. That contract handles assets bridged from Axelar to Secret.
Axelar said the incident hit assets bridged over IBC to Secret. Immediately upon awareness, its emergency committee disabled the Secret and Secret-SNIP connections.
The team stressed that the damage stayed contained. According to the statement, Axelar’s core protocol was not affected. No other IBC connections or native Secret tokens appear impacted.
Secret Network posted a matching message at nearly the same minute. As a result, both teams framed this as a coordinated, joint disclosure. Neither side pointed fingers.
Axelar also said it is contacting exchanges and law enforcement. Meanwhile, the team is preparing a detailed post-mortem. That report is not public yet.
Axelar is a cross-chain network. It links Cosmos and EVM ecosystems through its own chain and a messaging layer called GMP.
Secret Network is a privacy-focused smart contract chain. It uses trusted execution environments, so its code is public but its data stays encrypted.
The two connect over IBC, the Cosmos standard for cross-chain transfers. This specific route moved assets from Axelar into Secret since roughly 2022. Now that route is frozen.
ICS-20 is the Cosmos standard for moving tokens between chains over IBC. It verifies a packet, then mints or releases a matching token on the receiving chain.
On Secret, that contract handles incoming assets bridged from Axelar. So the flaw appears to live in how it validated those incoming transfers.
According to Axelar and early forensics, token representations could appear without a valid incoming packet. In other words, it resembles a classic unbacked minting bug.
Still, the precise root cause stays unconfirmed for now. The affected code sits in the public ics20-for-axelar repository. The promised post-mortem should detail the exact fault.
Secret Network encrypts balances and transfers by default. Because of that design, the exploit transactions and the attacker’s wallet stay hidden from public explorers.
This privacy normally protects ordinary users. However, it also slows attribution. It complicates any attempt to trace or freeze the stolen funds.
Researchers have still pinned down the victim contract. Coverage from The Crypto Times points to secret1yxjmepvyl2c25vnt53cr2dpn8amknwausxee83. That account is the gateway for the Axelar bridge channels.
You can view it on Mintscan. Even so, the encrypted ledger keeps the exact malicious calls invisible on-chain.
Timeline of the Secret Network ICS-20 Exploit
An attacker exploits a vulnerability in the Secret-side ICS-20 smart contract, draining approximately $4.67 million in bridged assets originating from the Axelar ecosystem. Due to Secret Network’s encrypted architecture, public transaction hashes and exact transfer timestamps are not available.
Secret Network publishes an official statement acknowledging the exploit and confirms that the incident is isolated to the Secret-side ICS-20 contract rather than the broader network infrastructure.
Axelar Network releases its own public disclosure, confirming the exploit details and announcing that emergency response procedures have been activated to contain the incident.
Axelar’s emergency committee disables the Secret and Secret-SNIP IBC connections. The bridge links are paused to prevent any additional unauthorized asset movements while investigations begin.
Following the shutdown of affected bridge routes, the Secret Network and Axelar teams begin coordinating incident-response efforts, including outreach to centralized exchanges and relevant law-enforcement agencies.
Both teams continue investigating the exploit and preparing a technical post-mortem. No recovery, reimbursement, compensation plan, or confirmed asset recovery has been publicly announced so far.
Cross-chain bridges remain a favorite target for attackers. Over recent years, contract bugs and packet flaws have drained large sums across the industry.
This case fits that pattern, yet the response stands out. According to both teams, the kill switch landed within minutes of detection.
That speed matters. Because the connections went down fast, the affected route could not bleed further while the teams investigated.
Axelar has leaned on its emergency committee before. This time, that same playbook isolated the damage to a single Secret-side contract.
The financial damage looks modest against Secret’s footprint. According to DefiLlama, Secret Network’s total value locked sits near $1.53 million.
Price reaction stayed limited in the first hours. SCRT traded around $0.055 to $0.058. AXL hovered near $0.045, with only minor moves.
One outlet, ValueTheMarkets, reported the loss closer to $4.3 million. Most sources, though, cite the ~$4.67 million figure from Axelar directly.
None of this is financial advice. Always verify on-chain data and primary statements before acting on any exploit report.
Reactions on X stayed mixed but measured. Many users praised the quick shutdown and the transparent, joint statement.
Others voiced familiar bridge fatigue. Some replies argued that cross-chain bridges keep failing as a category.
Still, the dominant note leaned toward relief. Because the teams contained the leak fast, several observers called the situation under control.
Several key questions stay open. The teams have not released a token breakdown, an attacker identity, or any recovery status.
For now, the disabled connections keep the affected route frozen. According to both teams, that containment should prevent further loss.
The next milestone is the post-mortem. Once Axelar publishes it, the report should confirm the bug, the assets taken, and any plan to repay users.
Watch the Secret Network and Axelar channels for that update. The Axelar Secret Network hack is recent, so expect the official picture to sharpen soon.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets
Bybit Disavows “BILLI” Token and BybitBilli Account as Scam
Verus Ethereum Bridge Hack Drains $7.5M in Repeat Exploit
Zilliqa Confirms ZIL Hack From Exchange Partner’s Cold Wallet
notnullOSX Malware Targets Mac Users With Crypto Wallets