Secret Network's Axelar Bridge Drained for $4.67M via Infinite-Mint Exploit, Undetected for Seven Days

WAXL2.61%
ATOM0.05%
According to Common Prefix, an attacker drained $4.67 million from Secret Network's Axelar bridge on June 10 via an infinite-mint exploit in a custom token contract, with the theft remaining undetected for seven days. The attacker exploited a flaw in the modified CW20-ICS20 contract by opening an independent Cosmos chain, establishing a channel to the bridge, and minting Secret-wrapped tokens without proper verification of transfer sources. The drain affected seven tokens: saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB, and sawstETH. The vulnerability was discovered on June 17 when a cross-chain transfer failed, revealing insufficient collateral in the escrow account. Axelar's emergency committee has disabled the Secret connections, and approximately $770,000 of the stolen funds remained in the attacker's wallet at the time of disclosure.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments