News linked to both this project and an event.
: Cross-chain protocol Axelar Network has issued a statement regarding the recent security incident related to Secret Network, clarifying that there is a misunderstanding within the community. Neither Axelar nor the Inter-Blockchain Communication Protocol (IBC) was attacked or compromised. The affected token smart contract was not developed, deployed, or maintained by Axelar. Furthermore, Axelar's firewall mechanism prevented the impact from spreading to other chains.It is reported that the exploited contract was a fork based on the CW20-ICS20 implementation, but the developers removed two core security checks, leading to an "infinite mint" vulnerability. By deleting the verification mechanisms originally designed to prevent such issues, this fork altered the contract's original trust model and was not subjected to a new security audit.Axelar Network explained that anyone can deploy contracts via IBC for wrapping cross-chain assets, and similar contracts are used to wrap tokens from other chains onto Secret Network. However, the specific fork on the Secret side in this incident contained a vulnerability due to the removal of critical security checks. This incident was not caused by an inherent logic flaw or an issue with the IBC protocol itself, but rather a security risk introduced by modifications made to the third-party contract.
Axelar stated that, upon discovering the incident, its emergency response committee immediately disabled the Secret and Secret-SNIP connections. The team is currently coordinating with relevant exchanges and law enforcement agencies. This incident is confined solely to assets bridged from Axelar to Secret via IBC; all other IBC connections, Secret tokens, other Axelar integrations, and the Axelar core protocol remain unaffected.
Axelar Network stated that the hacker attack and theft of funds undermine users’ overall trust in blockchain systems and slow down the adoption of the global ledger it envisions. Axelar expressed its support for the LayerZero team in navigating this difficult situation and rebuilding trust. Regarding this approximately $290 million attack, Axelar emphasized that—pending final forensic findings—the incident once again highlights the need for multi-layered security in cross-chain bridge construction. This includes ensuring operational security for bridge operators, validators, and validating nodes; providing proper incentives and training; and removing validators whose technical capabilities are not adequately demonstrated. Additionally, operators must be sufficiently numerous, structurally heterogeneous, diverse, and geographically distributed to prevent ultimate control by a single entity.