Axelar
Approved for: positions on Ethereum. The limits are in the memo below.
We approve Axelar with conditions as a dependency, making it the second cross-chain messaging layer in this registry to clear the bar that LayerZero and Wormhole did not. Axelar is a proof-of-stake chain of roughly 70 validators that observe and vote on cross-chain events. Consensus requires about 67% of voting power, after which the validators jointly produce an outbound message through threshold-signature cryptography, so no single validator can authorize a transfer alone. Voting weight is quadratic in stake, a deliberate design choice that limits large-holder dominance. Staking is real, delegated, and subject to penalties for downtime and double-signing. That provides disclosed economic security, not reputation alone, unlike the already-rejected Wormhole’s fixed 19-node Guardian quorum. A June 2026 incident tested the emergency response directly: an attacker exploited a vulnerable receiving-side contract on Secret Network, not Axelar’s own validator or threshold-signature layer, and Axelar’s emergency committee disabled the affected connection after discovery. Like CCIP, this entry covers a dependency, not a directly-custodied position. This approval does not cover a specific integration’s receiving-side contract, which a client must still verify on its own.
- Any confirmed exploit of Axelar’s own validator consensus, threshold-signature, or gateway-contract layer, as distinct from a downstream receiving-side integration failure
- Emergency committee composition, authority, and activation threshold are publicly disclosed and independently verifiable
- The 67% consensus quorum or 60% chain-maintenance threshold is lowered without public governance disclosure
- Validator count or stake concentration drops materially, reducing the practical difficulty of assembling a 67% quorum
Watched nightly: a warning on its venues or files, or a cited document that changes, reopens the memo. The first confirmation is due 2026-11-17.
The research file
Mechanism
Axelar is a proof-of-stake Cosmos SDK chain with roughly 70 active validators as of April 2026. Consensus on an inbound cross-chain event requires about 67% of voting power. Validators then jointly produce an outbound message through threshold-signature cryptography, so a transfer requires the group rather than any single party. Voting weight is quadratic, using the square root of stake, specifically to reduce large-holder dominance compared with simple stake-weighted voting. A separate 60% ”chain maintenance” quorum threshold determines whether cross-chain messaging from a given connected chain stays enabled. Below it, that chain’s routes halt automatically.
Control and governance
Each connected EVM chain has a Gateway contract that all Axelar validators jointly control through threshold signatures, not a small fixed multisig. Gateway upgrades require an on-chain governance proposal and a vote by staked AXL holders, followed by execution through a delayed multisig. Rate limits follow the same path but can be changed faster during emergencies. Staking is delegated with a low minimum. Penalties apply for downtime (0.01% of stake per block, capped at 1.75%) and double-signing (2% of stake), providing real, disclosed economic security rather than reputation alone. An emergency committee exists and has used its authority, though this review did not confirm its exact composition or activation threshold.
Incident record
On 2026-06-10, an attacker exploited a modified CW20-ICS20 contract on Secret Network, the third-party bridge-receiving side rather than Axelar’s own core infrastructure. The attacker used a forged-channel infinite-mint attack to mint about $4.67M of unbacked wrapped tokens. The attack went undetected for about seven days because Secret uses privacy by default. Axelar’s emergency committee disabled both Secret and Secret-SNIP connections upon discovery. The confirmed root cause was in Secret’s own IBC contract, not Axelar’s validator or threshold-signature layer, and we found no exploit of Axelar’s core mechanism. This case shows that Axelar’s emergency response worked as intended for a downstream integration failure. It also shows that risk in each receiving-side integration sits outside Axelar’s validator security and needs a separate review, the same caveat this registry already applies to LayerZero and CCIP integrations.
Exit and dependency framing
Like LayerZero and CCIP, Axelar provides infrastructure that other protocols build on, not a product with its own deposit and withdrawal flow that we can test directly. Any Ketju-approved position routed through an Axelar-secured integration depends on that integration’s receiving-side contract. The June 2026 Secret Network incident gives a concrete example of why Axelar’s validator security does not automatically protect every downstream contract built on it.
Comparison
Axelar is stronger than the already-rejected Wormhole/Portal, whose 19 Guardians have no staking or slashing and suffered a $325M forgery loss in 2022. Axelar’s validators have economic stakes and face penalties, while quadratic weighting limits concentration. It also differs from the already-rejected LayerZero, which defaults many integrators to a single DVN operator. Axelar’s 67% quorum is a standing protocol-level rule, not an optional choice that each integration’s deployer can weaken. Axelar is closest in design to the approved CCIP. Both use a structural safeguard, Axelar’s proof-of-stake quorum with penalties and CCIP’s independent Risk Management Network, that does not depend by default on one trusted operator. Both also had their most notable 2026 incident occur in a downstream integration rather than their own core control layer.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Axelar Documentation — learn · primary · accessed 2026-08-17
Supports: protocol overview - Axelar Documentation — EVM contract governance · primary · accessed 2026-08-17
Supports: gateway upgrade path, delayed multisig, rate limits - Axelar — a technical introduction to the Axelar network · primary · accessed 2026-08-17
Supports: 67% consensus quorum, quadratic voting, threshold signatures - Axelar Documentation — security overview · primary · accessed 2026-08-17
Supports: security architecture - Exodus — staking Axelar (AXL) FAQs · secondary · accessed 2026-08-17
Supports: validator count, staking and slashing mechanics - The Block — Secret Network’s Axelar bridge drained for $4.67 million in infinite-mint exploit · secondary · accessed 2026-08-17
Supports: June 2026 incident, root-cause attribution to Secret - Secret Network Forum — security incident: Axelar-Secret IBC bridge exploit · primary · accessed 2026-08-17
Supports: primary incident disclosure
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |