A breach of cross-chain assets that came to light in mid-June left Secret Network at a loss of approximately $4.67 million. The problem is not in the Axelar network itself, but in a custom-defined token contract on the Secret Network. By so doing, the attackers forged satokens, which were not backed by real collateral, and removed the trust assets through a normal foreclosure process.
The leak was discovered a week later.
The attack occurred on 10 June but was not detected until 17 June. The alarm was triggered by a failed cross-chain transaction, when the system had “under-funded” errors and subsequently revealed that trust assets had been vacated.
Common Prefix, the block chain research institute, stated that the problem was that the contract did not correctly verify the origin of the transferred assets. That is, the system did not confirm the existence of the relevant deposits before the casting of the assets.
As a result, the attackers can falsify their deposit records through communication channels under their control, creating satokens that look normal but are not actually supported by collateral. The coins were subsequently redeemed through the legal Axelar channel in exchange for the real assets that had been locked in the hosting address.
Affected assets include USDT and WBTC
The assets affected included saUSDT, saUSDC, saDAI, saWETH, saWBBTC, saWBNB and sawsteh.
Reports indicate that when the attackers were able to do so, the money bridge was handed over to the Ether factory and converted to ETH, and was diverted to approximately 30 wallets to reduce the difficulty of tracing. Some of the stolen assets subsequently went to centralized platforms, including KuCoin, Changenow and HitBTC.
This is one of the larger encrypted security incidents this month, according to DeFiLlama. During the same period, more than 20 incidents of protocol attacks or loopholes were recorded, with losses on a larger scale than the incidents, with only two cases involving Humanity Protocol and Syscoin Bridge.
Part of the token or full support lost
After the incident was made public, Secret Network reminded users holding the Axelar Bridge to saTokens that the assets in question might no longer be fully encumbered and that the funds were at risk of loss. At the same time, the projector stated that the original token SCRT was not within the scope of the impact.
Axelar then stated separately that the Axelar network itself and the IBC cross-chain communication protocol had not been breached. It is argued that the loophole arose from a third-party token contract, which was not developed, deployed or maintained by Axilar.
This means that the focus of incident responsibility is now focused on the logic of encapsulation and casting of specific assets rather than on the bottom-up cross-chain network itself. The most immediate question for users holding the relevant saTokens is whether the collateral integrity of the assets will be restored.
