According to Bitcoinist, on June 19, the Axelar bridge connection to Secret Network was suspended after a reported $4.67 million exploit involving an infinite-mint vulnerability. The attacker allegedly used forged IBC packets to mint unbacked wrapped assets such as saUSDT and saUSDC by exploiting a validation gap in the CW20-ICS20 contract that failed to properly verify the source channel of incoming IBC messages.
The exploit occurred on June 10 but went undetected until June 17, when the bridge connection was subsequently disabled on June 19 to contain the issue. The attacker reportedly created a private Cosmos chain and injected forged packets to mint unbacked assets, then redeemed them against assets held in escrow to convert fake supply into real value.