It took seven full days for anyone to realize $4.6
#World Cup Predictions: 100,000 USDT Daily #HTX Invites You to Share 600K USDT in Gift Packs #BTC Prophet: 20-Day 380 Million HTX Challenge It took seven full days for anyone to realize $4.67 million had walked out of the Axelar to Secret Network bridge. The drain happened on June 10, and nobody on either side noticed until June 17, when a routine cross-chain transfer failed and someone went to check the escrow balance on the Axelar side. The account was empty. Because Secret Network is built around a privacy-by-default design where contract state and transaction details are shielded from public view, the on-chain footprints that usually tip off security researchers within minutes were simply invisible. That gave the attacker an entire week of breathing room while the funds were quietly moved off. Axelar's emergency committee has since disabled the Secret and Secret-SNIP connections, but the money is already gone.
An infinite-mint bug, wrapped in a custom contract
The vulnerability lived in a modified CW20-ICS20 contract on the Secret side of the bridge, which is the piece of code that handles inbound assets arriving over Cosmos IBC and mints Secret-wrapped versions of them. Those wrapped versions are the saTokens that DeFi users on Secret actually hold and trade. The attacker is accused of doing something elegantly simple: spinning up their own single-validator Cosmos chain, opening a brand new IBC channel directly to the Secret bridge contract, then self-relaying forged packets that carried token denominations matching the contract's allow-list. The contract checked which denomination was coming in. It did not check which channel that denomination was supposed to be coming from.
That single missing check is the entire story. Because the saToken contract trusted any properly-formatted IBC packet carrying a known denomination, the attacker was free to mint fully-backed-looking saUSDT, saUSDC, saDAI, saWETH, saWBTC, saWBNB and sawstETH out of thin air. Those fresh
Todos os comentários0Mais recentePopular