Skip to main content

Secret Network Hit With $4.67M Infinite Mint Exploit Losses



An attacker exploited an “infinite mint” vulnerability in a smart contract on Secret Network to create wrapped versions of Axelar-backed assets without the normal backing. According to Common Prefix, the resulting loss reached $4.67 million, with the incident first occurring on June 10 and later being detected on June 17 after irregularities surfaced during a failed cross-chain transfer.



The exploit relied on a flaw in how inbound transfers were handled: the contract minted genuine saTokens without verifying that the tokens being deposited originated from a legitimate source. After discovery, the attacker redeemed the forged saTokens through Axelar’s standard routes, draining the real wrapped assets held in escrow. Common Prefix reported the issue on Friday, citing on-chain findings and the sequence of redemptions.



Key takeaways



  • An “infinite mint” bug on Secret Network allowed unbacked Axelar-wrapped assets (saTokens) to be minted.

  • The vulnerability stemmed from missing verification of the inbound transfer source before minting, enabling forged deposits to produce real tokens.

  • Common Prefix estimates the exploit’s impact at $4.67 million, with detection coming a week after the June 10 attack.

  • The attacker redeemed saTokens back to the underlying assets held in escrow, then moved proceeds to Ethereum and split holdings across multiple wallets.

  • Axelar said its network and IBC were not compromised, and that the affected contract was not developed or maintained by Axelar.



How the Secret Network “infinite mint” unfolded


The Secret Network incident centered on a smart contract that minted Axelar-wrapped tokens (saTokens) tied to assets held in escrow. Common Prefix’s analysis indicates the contract did not verify the source of inbound transfers prior to minting. As a result, deposits that were forged over an attacker-controlled channel could trigger minting of genuine saTokens without corresponding backing assets.



Common Prefix said the attacker then redeemed those Axelar-wrapped saTokens back through legitimate channels. Because the real wrapped assets were stored in escrow, the redemption process allowed the attacker to withdraw the backed collateral that should have corresponded to the issued tokens. In short, the breach converted what should have been a “wrapped claim” into an extractable withdrawal by breaking the token-to-collateral link at the minting stage.



Assets targeted and the size of the exploit


Common Prefix reported that multiple Axelar-wrapped tokens were minted without backing. The affected set included saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBTC? and saBNB, as well as sawstETH (as listed in Common Prefix’s report). The firm estimated the total exploit impact at $4.67 million.



Secret Network is a privacy-focused layer-1 blockchain in the Cosmos ecosystem. Axelar, meanwhile, is an interoperability network designed to connect different blockchain ecosystems. The incident highlights the risk that can arise when wrapped assets and cross-chain messaging rely on correct validation logic—especially when minting depends on the integrity of inbound transfer proofs.



Discovery, attacker movement, and where funds ended up


While the exploit happened on June 10, Common Prefix said it wasn’t detected until June 17. The delayed discovery was linked to a failed cross-chain transaction that returned an “insufficient funds” error involving the drained account. That error drew attention to the fact that tokens had likely been minted without sufficient backing.



After redemption, Common Prefix reported that the attacker moved the stolen assets to Ethereum and converted the proceeds to Ether (ETH). The firm also said the attacker split the funds across roughly 30 wallets, eventually depositing with exchanges including KuCoin, ChangeNow, and HitBTC—details that matter for monitoring and potential recovery efforts, since multi-wallet distribution can slow down tracing and enforcement.



Secret Network and Axelar respond: what was and wasn’t compromised


Secret Network posted a security incident warning, advising holders of Axelar-bridged saXXX tokens on Secret that the backing for those tokens was affected and that their funds may be lost. The warning, published after the incident became public, focused on user risk rather than suggesting that all tokens on Secret were compromised.



Axelar addressed the incident separately after “some confusion” circulated around the breach. In a post on Saturday, Axelar stated that neither Axelar nor IBC was compromised. It also said the exploited token smart contract was not developed, deployed, or maintained by Axelar, and that Axelar’s firewalling helped prevent broader impact across chains. For users and builders, the distinction matters: it suggests that the failure was contained to the contract logic on Secret’s side of the integration rather than a systemic breach across the broader Axelar interoperability stack.



Why this case fits a broader pattern of bridge and wrap exploits


Common Prefix placed the Secret Network hack in the context of a busy month for crypto exploits. According to DeFiLlama data cited in the article, crypto protocol hacks and exploits now number at least 22 for the month, reflecting continued pressure on cross-chain infrastructure and token-wrapping mechanisms.



Earlier this month, Cointelegraph reported major losses tied to other cross-chain incidents, including Humanity Protocol and Syscoin Bridge, which lost $32 million and $8 million, respectively. Together, these cases underscore a recurring theme: cross-chain systems can fail at multiple layers—message validation, escrow accounting, wrapped-token minting, and redemption logic—meaning that a vulnerability in one link can lead to direct fund drains if the surrounding checks are incomplete.



For investors and traders, the practical implication is that token “existence” on a destination chain does not always guarantee collateral backing. In the Secret Network incident, the tokens were minted in a way that broke that assumption, turning wrapped representations into potentially uncollectible claims. For developers, the bigger lesson is straightforward: minting logic that depends on inbound data must treat verification as part of the core security model, not an optional step.



Looking ahead, users holding affected saTokens on Secret should monitor Secret Network’s incident updates and any follow-on recovery or remediation announcements. Meanwhile, builders integrating interoperability routes should watch closely for contract-level fixes and updated validation requirements—because as this exploit shows, a single missing verification step can propagate into real withdrawals from escrow even when the interoperability provider itself insists it was not compromised.



https://www.cryptobreaking.com/secret-network-hit-with-4/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Secret%20Network%20Hit%20With%20$4.67M%20Infinite%20Mint%20Exploit%20Losses%20

Comments

Popular posts from this blog

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...