The Secret post-mortem is out. The real story: the people who modified that bridge didn't understand how its own authentication worked. No outside auditor was ever asked to check it. And for three years, no attacker understood it either. The bridge held until (my bet) an AI finally read the contract and saw what every human had missed.
The miss is almost dumb in hindsight. The contract started as an escrow bridge, a coat check: it only ever hands back a coat someone checked in earlier, so "is this deposit real?" was answered for free by the ticket logic.
Then it was forked to mint Axelar tokens instead. Minted tokens were never checked in, so the ticket logic didn't fit and got deleted. Whoever did that didn't realize those exact functions were the only thing verifying which chain a deposit came from. The Allow List that replaced them checked which token could be minted, never its source.
So the door was open from January 2023. Then someone spun up a fake chain, named a real asset like USDT, and minted $4.67M out of nothing.
The lesson isn't really about Secret. For three years, finding this took a human willing to read the whole contract, and nobody did. That barrier is gone. An AI reads all of it, closely, for cents. So if your contract is public and hasn't been through an AI audit, assume the attacker's AI is already reading it. Audit yours first.
Axelar Live Price data
Axelar AXL Price History USD
Own AXL Now
Buy and sell AXL easily and securely on BitMart.Axelar X Insight
Secret post-mortem https://t.co/kBT1f9Xu0H
Axelar–Secret Bridge Exploited for $4.67M
@Axelar confirmed around $4.67 million in tokens were drained from assets bridged over IBC to Secret Network.
Where the Flaw Was:
The issue was isolated to the Secret-side ICS-20 contract that handles assets from the Axelar chain. Axelar's core protocol, other IBC connections, and native Secret tokens are safe.
Why It Is Hard to Trace:
Secret is a privacy chain, so transactions and balances are encrypted. The exploit transaction is invisible on-chain, making tracking the attacker difficult.
Axelar disabled the Secret and Secret-SNIP bridge connections and is now working with exchanges and law enforcement to track the funds.
Bridges remain one of DeFi's biggest risk points. Be careful with cross-chain transfers and wait for official updates before moving funds.
Axelar prevented contagion
A connected chain suffered an exploit and Axelar successfully contained it.
This is the strongest argument for the purge. https://t.co/PNzoI5YnqQ
Secret Network incident analysis by @CommonPrefix. Axelar's protocol was not compromised and prevented contagion from spreading to other chains. Here's the full report: https://t.co/u7izAFQu7I
Price Prediction
When is a good time to buy AXL? Should I buy or sell AXL now?
Beacon Prediction
Probabilistic Price Forecast (Next 24 Hours)This prediction is an experimental technical product and is provided for reference purposes only. It does not constitute investment advice. Unexpected real-world events may significantly impact market behavior. Traders should make decisions with caution.
