Axelar
The scheduled date is the outside bound. Kill criteria are checked every day, and a trigger reopens the memo that week.
APPROVED WITH LIMITS, AS A DEPENDENCY, THE SECOND CROSS-CHAIN MESSAGING LAYER IN THIS REGISTRY TO CLEAR THE BAR LAYERZERO AND WORMHOLE DID NOT. Axelar is a proof-of-stake chain of roughly 70 validators that observe and vote on cross-chain events, requiring about 67% of voting power for consensus, then jointly produce an outbound message via threshold-signature cryptography so no single validator can authorize a transfer alone. Voting weight is quadratic in stake, a deliberate design choice limiting large-holder dominance. Staking is real, delegated, and slashable for downtime and double-signing — disclosed economic security, not reputation alone, unlike the already-rejected Wormhole’s fixed 19-node Guardian quorum. A June 2026 incident tested the emergency response directly: an attacker exploited a vulnerable receiving-side contract on Secret Network, not Axelar’s own validator or threshold-signature layer, and Axelar’s emergency committee disabled the affected connection on discovery. Like CCIP, this entry is modeled as a dependency, not a directly-custodied position, and this approval does not certify a specific integration’s receiving-side contract, which a client must still verify independently.
- Any confirmed exploit of Axelar’s own validator consensus, threshold-signature, or gateway-contract layer, as distinct from a downstream receiving-side integration failure
- Emergency committee composition, authority, and activation threshold are publicly disclosed and independently verifiable
- The 67% consensus quorum or 60% chain-maintenance threshold is lowered without public governance disclosure
- Validator count or stake concentration drops materially, reducing the practical difficulty of assembling a 67% quorum
The research file
Mechanism
Axelar is a proof-of-stake Cosmos SDK chain with roughly 70 active validators as of April 2026. Consensus on an inbound cross-chain event requires about 67% of voting power; validators then jointly produce an outbound message through threshold-signature cryptography, so authorizing a transfer requires the collective, not any single party. Voting weight is quadratic, the square root of stake, specifically to reduce large-holder dominance versus simple stake-weighted voting. A separate 60% ”chain maintenance” quorum threshold governs whether cross-chain messaging from a given connected chain stays enabled at all; below it, that chain’s routes halt automatically.
Control and governance
Each connected EVM chain has a Gateway contract jointly controlled by a key held across all Axelar validators via threshold signatures, not a small fixed multisig. Gateway upgrades require an on-chain governance proposal voted on by staked AXL holders, executed via a delayed multisig; rate limits follow the same path but can be adjusted faster for emergencies. Staking is delegated with a low minimum; slashing penalizes downtime (0.01% of stake per block, capped at 1.75%) and double-signing (2% of stake) — real, disclosed economic security rather than reputation alone. An emergency committee exists and has exercised real authority, though its exact composition and activation threshold were not confirmed in this review.
Incident record
On 2026-06-10, an attacker exploited a modified CW20-ICS20 contract on Secret Network, the third-party bridge-receiving side, not Axelar’s own core infrastructure, to mint about $4.67M of unbacked wrapped tokens via a forged-channel infinite-mint attack, undetected for about seven days due to Secret’s privacy-by-default design. Axelar’s emergency committee disabled both Secret and Secret-SNIP connections upon discovery. The confirmed root cause sat in Secret’s own IBC contract, not Axelar’s validator or threshold-signature layer, and no exploit of Axelar’s own core mechanism was found. This is a useful precedent: it demonstrates Axelar’s emergency response worked correctly for a downstream integration failure, while also showing that per-integration risk on the receiving side sits outside Axelar’s own validator security and needs separate scrutiny, the same caveat this registry already applies to LayerZero and CCIP integrations.
Exit and dependency framing
Like LayerZero and CCIP, Axelar is infrastructure other protocols build on, not a product with its own deposit and withdrawal flow to test directly. Any Ketju-approved position that routes through an Axelar-secured integration inherits that specific integration’s own receiving-side contract as a dependency, and the June 2026 Secret Network incident is a concrete reminder that Axelar’s own validator security does not automatically extend to every downstream contract built on top of it.
Comparison
Stronger than the already-rejected Wormhole/Portal, whose 19 Guardians carry no staking or slashing and suffered a $325M forgery loss in 2022 — Axelar’s validators are economically staked and slashable, with quadratic weighting limiting concentration. Different from the already-rejected LayerZero, which defaults many integrators to a single DVN operator: Axelar’s 67% quorum is a standing protocol-level requirement, not an opt-in per-integration choice a deployer can under-configure. Closest in spirit to the approved CCIP: both have a structural mechanism, Axelar’s slashable proof-of-stake quorum and CCIP’s independent Risk Management Network, that does not rely on a single trusted operator by default, and both had their most notable 2026 incident sit in a downstream integration rather than their own core control layer.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Axelar Documentation — learn · primary · accessed 2026-08-17
Supports: protocol overview - Axelar Documentation — EVM contract governance · primary · accessed 2026-08-17
Supports: gateway upgrade path, delayed multisig, rate limits - Axelar — a technical introduction to the Axelar network · primary · accessed 2026-08-17
Supports: 67% consensus quorum, quadratic voting, threshold signatures - Axelar Documentation — security overview · primary · accessed 2026-08-17
Supports: security architecture - Exodus — staking Axelar (AXL) FAQs · secondary · accessed 2026-08-17
Supports: validator count, staking and slashing mechanics - The Block — Secret Network’s Axelar bridge drained for $4.67 million in infinite-mint exploit · secondary · accessed 2026-08-17
Supports: June 2026 incident, root-cause attribution to Secret - Secret Network Forum — security incident: Axelar-Secret IBC bridge exploit · primary · accessed 2026-08-17
Supports: primary incident disclosure
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |