A hack occurred in the Secret ecosystem, affecting wrapped assets related to cross-chain transfers. The attacker was able to mint tokens without real backing and exchange them for actual reserves.
The damage is estimated at nearly $4.7 million. The incident itself happened on June 10, but it was noticed later when one of the cross-chain operations failed due to insufficient funds at the drained address.
The System Mistook an Empty Deposit for a Real One
The vulnerability was due to improper verification of incoming transfers. The contract did not ensure that the deposit came from a trusted source, so it started minting wrapped tokens based on data controlled by the attacker.
After that, the attacker used the standard redemption mechanism. They returned the unbacked tokens and received real assets from the reserves in exchange.
This type of error is especially dangerous for bridges. On the surface, everything looks like normal protocol operation, but internally, the main condition is violated: every minted token must be fully backed by an asset in another network.
Wrapped Versions of Major Assets Were at Risk
The attack involved wrapped versions of stablecoins, ETH, BTC, BNB, and stETH. For users, this is a painful scenario because such assets are often perceived as full equivalents of the original coins in another network.
In practice, this is not the case. A wrapped token relies on trust in the bridge, the contract, and the reserve. If the minting happened without a real deposit, its value becomes a question for the infrastructure, not the underlying asset.
Secret warned holders of affected tokens that their backing might have been compromised. This means that some funds may be lost.
The Money Was Split Up and Began to Be Withdrawn
After the attack, the assets were transferred to Ethereum and converted to ETH. Then the sum was distributed among dozens of wallets to make further tracking more difficult.
According to analysts, part of the funds was later sent to centralized platforms and exchange services. This route is often used after hacks: first splitting, then trying to withdraw assets through several channels.
That is why detection speed plays an important role. If the problem is discovered a week later, the funds have already passed through various networks, wallets, and services.
Axelar Says Its Infrastructure Was Not Affected
After the incident, the Axelar team separately clarified that its network and the IBC cross-chain protocol were not hacked. According to them, the problem was in a third-party contract that was neither developed nor maintained by Axelar.
The project also stated that protective mechanisms limited the spread of damage to other networks. This is an important clarification for the market because attacks on wrapped assets often create confusion between the bridge, the network, and a specific contract.
For users, however, the technical distinction changes little in the end. If the token in their wallet lost its backing, the risk has already materialized, even if the underlying protocol was not hacked.
The Problem Was Found Too Late
The most alarming point is not just the amount of damage, but the delay in detection. The hack was not stopped immediately. It became known after a failure, when the reserve could no longer complete the next operation.
This shows a weak spot in bridge monitoring. Simply watching individual transactions is not enough. It is necessary to constantly reconcile three things: how many tokens have been minted, how many have been redeemed, and how many real assets are in the reserve.
If this reconciliation is delayed, users only find out about the hole in the backing after the assets are gone.
June Was a Tough Month for Bridges
The incident occurred amid a series of attacks on crypto protocols. According to DeFiLlama, there were at least 22 hacks and exploits in June.
Among major cases were already attacks on Humanity Protocol and Syscoin Bridge. The damage there was estimated at tens of millions and several million dollars, respectively.
Against this backdrop, the Secret hack became another reminder that cross-chain solutions remain one of the riskiest parts of the market. They connect different blockchains, hold reserves, and depend on correct verification of messages between networks.
Project Tokens Remain Far From Highs
The SCRT token itself, according to the project, was not directly affected by the attack. But its market performance remains weak: the asset trades around $0.058 and is about 99% below its 2021 high.
AXL also remains far below its historical peak. The token trades around $0.045, which is about 98% below its 2024 high.
For infrastructure projects, such incidents are especially unpleasant. When the market already values tokens at a steep discount, a new security issue raises further questions about the trust and resilience of the ecosystem.
What Happens Next?
Secret needs to disclose the full picture for affected assets: which tokens lost their backing, how much can be recovered, and what users who held wrapped versions of assets in the network should do.
For the industry, the main lesson is broader than a single project. Bridges must verify not only the fact of an incoming message but also its source. Any error in this logic can turn an empty deposit into a real withdrawal from reserves.
The main takeaway is simple. The Secret hack happened because a basic principle of backing was violated. The contract minted wrapped assets without a real deposit, and the attacker exchanged them for real funds. Until bridges learn to detect such discrepancies faster, they will remain one of the main targets for hackers.
Read More: Dash Explores the Philippines for Crypto Payments Launch