Axelar’s Secret Network bridge exploit shows how long minting flaws can stay hidden

Axelar’s bridge connection to Secret Network was drained for $4.67 million through an infinite-mint flaw that reportedly went undetected for seven days. The case is a reminder that bridge security depends on both contract design and fast anomaly detection.

Arjun Renapurkar

The Axelar bridge linked to Secret Network was exploited through an unchecked minting vulnerability, resulting in a loss of $4.67 million over a period of seven days before detection.

Axelar’s bridge connection to Secret Network was exploited through an infinite-mint flaw, and the loss was reported at $4.67 million. The incident matters now because it shows how a bridge contract can be abused for days before detection, turning a code flaw into a prolonged treasury and liquidity problem rather than a one-off theft.

What happened in the Axelar-Secret Network exploit?

Reporting from The Block, The Defiant, Cryptometer, and Forklog says the attacker exploited a minting vulnerability in the bridge contract and drained wrapped stablecoins over a period that went unnoticed for seven days. Forklog says Axelar disclosed the breach on June 19, while the other reports place publication on June 21 and 22, which is consistent with a June 2026 incident that was still being analyzed after disclosure.

Why does this matter beyond one bridge?

Bridge exploits are operationally important because they can affect users who rely on cross-chain transfers, wrapped assets, and liquidity routing. A minting flaw is especially serious because it can create unauthorized supply rather than simply move existing funds, which makes containment harder once the contract is live.

For protocols, the main lesson is that security is not only about audits at launch. It also depends on continuous monitoring for abnormal minting behavior, supply changes, and unexpected wallet activity. For users and treasury operators, the practical implication is that bridge risk should be treated as infrastructure risk, not just market risk.

What are the limitations and failure modes?

The source reporting indicates that the exploit went undetected for seven days, which is the clearest operational limitation here. That means the failure was not only the contract bug itself, but also the delay in spotting it. The practical response belongs with the bridge operator and any monitoring teams that track token supply, contract events, and cross-chain flows, because fast alerting is what shortens the time between misuse and containment.

Another limitation is that once value has moved, recovery is uncertain. The Block reported that roughly $770,000 remained in the attacker’s Axelar wallet and that Secret Network asked Axelar to freeze those funds, but Axelar declined. That illustrates a core constraint in decentralized systems: even when a loss is identified, response options may be limited by governance, technical control, or policy.

What should operators do next?

Operators that depend on bridges should review whether they can monitor mint events, set anomaly thresholds, and pause or isolate risky flows when behavior changes. They should also test incident playbooks for cross-chain assets, because the response window can be short even when the exploit itself lasts longer.

For finance and payments teams, the broader takeaway is to avoid assuming that a bridge is safe because it has been live for a long time. A years-old flaw can still be exploitable, and delayed detection can turn a technical bug into a balance-sheet event.

Radom’s crypto payments stack is built for teams that need to manage digital asset flows with operational discipline, but the broader point here is simpler: bridge exposure needs monitoring, not just trust.

FAQ: What is the most important lesson from this incident?

The most important lesson is that contract design and monitoring have to work together. A secure-looking bridge can still fail if minting behavior is not watched closely enough to catch abuse quickly.

Sources

Want more analysis like this?

Sign up to Radom to get started