
Axelar Network
#490
Signaling Proposal: Freeze Hacker Funds and Recustody to a Trusted Distributor at a Later Date
Proposal Type: Text (Signaling)
Proposal Contents (*the original text from the proposer)
SUMMARY
This is a non-binding signaling (text) proposal. It carries no automatic on-chain action. Its purpose is to establish a clear, on-chain record of community and validator intent regarding funds stolen in the June 10, 2026 Axelar–Secret IBC bridge exploit.
The proposal asks the community to signal support for two coordinated actions:
-
FREEZE: Affirm community and validator intent to freeze the stolen funds currently controlled by the attacker, so that they cannot be moved, swapped, or bridged out of the Axelar network while a recovery process is organized.
-
RECUSTODY (AT A LATER DATE): Affirm intent to, at a later date and via a subsequent binding proposal, recustody the frozen funds to a trusted, community-vetted distributor. That distributor would be responsible for returning the recovered assets to affected users according to a transparent, auditable distribution plan to be ratified by a future governance proposal.
BACKGROUND
On June 10, 2026, the Axelar–Secret IBC bridge was exploited. A detailed post-mortem of the incident is published at: https://forum.scrt.network/t/security-incident-axelar-secret-ibc-bridge-exploit-june-10-2026/7995
On-chain analysis identified the following address as the attacker-controlled wallet holding stolen funds: axelar1hzra9z4zn8q0w8f3dj2wnw0xgetu8dfdhl6ad8
MOTIVATION
The stolen assets belong to users of the bridge and the broader Axelar and Secret communities. Acting quickly to signal a coordinated freeze reduces the attacker's ability to launder or off-ramp the funds and maximizes the probability of a full recovery for affected users. Establishing intent now, transparently and on-chain, gives validators, integrators, and exchanges a clear mandate to support recovery efforts and lays the groundwork for a future binding proposal that specifies the exact recustody and redistribution mechanics.
WHAT THIS PROPOSAL DOES AND DOES NOT DO
- It DOES record formal community intent to freeze the identified attacker funds and to later recustody them to a trusted distributor for return to victims.
- It DOES create a public mandate that validators, the Axelar core team, exchanges, and integrators can reference when coordinating a response.
- It DOES NOT itself move, freeze, or seize any funds. As a text proposal it has no automatic on-chain effect.
- It DOES NOT name the trusted distributor or finalize the distribution plan. Those details will be brought to the community in a separate, binding follow-up proposal once a recovery path and distributor candidate have been vetted.
EXPECTED OUTCOME
A YES result signals that the Axelar community supports (a) an immediate coordinated freeze of the funds held at the identified attacker address, and (b) recustody of those funds, at a later date, to a trusted distributor for return to affected users. Following passage, contributors will prepare a binding follow-up proposal specifying the precise freeze mechanism, the chosen distributor, and the redistribution plan.
ADDRESSES REFERENCED
Attacker wallet (per post-mortem): axelar1hzra9z4zn8q0w8f3dj2wnw0xgetu8dfdhl6ad8 Post-mortem: https://forum.scrt.network/t/security-incident-axelar-secret-ibc-bridge-exploit-june-10-2026/7995
VOTING
YES — You support signaling intent to freeze the attacker funds and recustody them to a trusted distributor at a later date. NO — You do not support this signaling intent. NO WITH VETO — You believe this proposal is spam, harmful, or fundamentally inappropriate. ABSTAIN — You wish to contribute to quorum without taking a position.
Voting Results
Vox Populi
Community discussions related to the proposal.
There do not appear to be any discussions on this proposal at this time.