Secret Network
Programmable privacy, hardware trust and a contested community continuation.
Secret Network is a Cosmos-based chain for confidential smart contracts, with public SCRT used for fees, staking and governance. Its 2026 story includes a bridge exploit and the departure of Secret Labs. Foundation replies confirm a dilution mint, while leaving important questions about spending and victim remediation open.
Этот материал пока доступен на английском. Интерфейс использует выбранный вами язык.
Читать английский оригинал →Проверяем поддержку чтения вслух в браузере…
The native coin is public; contract privacy is programmable
Secret Network combines the Cosmos SDK, Rust-based CosmWasm contracts, encryption and Intel SGX trusted execution environments. Its native SCRT coin pays fees, supports proof-of-stake security and participates in governance. Native transfers are public. The privacy feature belongs to how Secret Contracts process protected messages and state, rather than to a promise that everything bearing the Secret name is anonymous. The documentation's introductory application and developer counts are historical promotional figures; they are not used here as a September 2026 census.
The original graypaper argues for applications that can use sensitive information without putting every input on a public ledger. It distinguishes encrypted contract messages from visible fields such as the sender, chain context and sent funds. That is a narrower and more useful proposition than invisibility. A user can want a private balance or confidential computation while still leaving public transaction metadata. The paper's old throughput, supply and governance parameters should not be carried forward as current measurements simply because the design explanation remains available.
Enigma's legal history is not a description of today's SCRT
The SEC's February 19, 2020 order concerns Enigma MPC's 2017 ENG offering. It records an approximately $45 million sale, registration violations and a settlement accepted without admission or denial of the findings apart from jurisdiction. This is a specific historical legal record about ENG and its issuer. It does not automatically classify every later SCRT transaction, promise an available refund today, or erase the distinction between an earlier token sale and the independent network that subsequently developed.
Enigma's later annual filing says it stopped developing its earlier protocol and joined development of the Secret Network community after concluding ENG would no longer function as intended in its planned decentralized system. The filing describes a February 2020 genesis organized by the community. Reading that account alongside the legal order helps explain why names, companies and tokens are easily confused. The company's description is evidence of its own decisions and role, not proof that it owned the resulting chain or every subsequent community organization.
Private contracts arrived through explicit network changes
On September 15, 2020, contributor jlwaugh announced that the mainnet upgrade enabling Secret Contracts had completed. The post addressed participants as Secret Agents and framed programmable confidentiality as a public infrastructure opportunity. That launch is a dated deployment milestone, distinct from the earlier chain genesis. Claims in the announcement about being first are promotional comparisons; the enduring technical event is that the chain acquired encrypted general-purpose contract execution.
Later security disclosures are part of evaluating that capability, rather than reasons to omit its development history.
The October 23, 2020 secretSCRT announcement explains the difference between native SCRT and a wrapped SNIP-20 representation. Users deposit native coins into a contract and receive a private token representation with contract-defined transfers, allowances and redemption. The distinction matters whenever a proposal treats native balances, staking and contract-held positions differently. Wrapping is not the creation of a second independent monetary base, and privacy does not remove the need to understand the wrapper's code, access controls and ability to honor redemption.
Choosing who may read private information
Viewing keys solve a particular query problem: an ordinary public query does not prove that its sender owns the address whose private data it requests. The contract stores a viewing credential associated with that address. Anyone holding the appropriate key and address can read the permitted information without possessing the spending key. This makes selective disclosure possible, but it also makes a viewing key sensitive. Sharing one for accounting or application access is a real permission decision, even though it need not authorize moving the underlying funds.
Query permits use signed messages identifying the relevant tokens and permissions instead of requiring a new on-chain viewing-key transaction. A contract verifies the signature before answering the query. This can reduce setup friction and unnecessary transactions, but the scope of the signed permission still matters. A request to reveal transaction history is different from a request to reveal a balance. The interface should expose that distinction clearly; a wallet signature is not harmless merely because the application describes it as logging in.
A real breach of the confidentiality assumption
The SGX.Fail researchers demonstrated that vulnerable hardware could expose Secret's consensus seed, the basis for decrypting protected information. They obtained mainnet and testnet seeds, published proof of compromise and said they destroyed the mainnet key material. Their account distinguishes confidentiality failure from ordinary consensus integrity: exposing private state need not rewrite balances, although assets relying on secret authentication material can face additional risks.
The disclosure is concrete evidence against treating hardware isolation as an unconditional guarantee or dismissing all hardware attacks as merely theoretical.
Secret Labs' January 2026 roadmap describes further lessons from wiretap.fail and tee.fail, followed by tighter control of machine admission. It presents governance-approved machines and hardware restrictions as a response to a changing threat model. Those controls introduce a participation tradeoff alongside the privacy objective. The page now carries a notice that Secret Labs is no longer involved with the network. Its technical history remains relevant, but unfinished work in that roadmap is not a promise from the current community stewards or proof that a feature shipped.
New releases narrow some risks without replacing the architecture
The March 30, 2026 v1.24.1 release blocks specified end-of-life hardware, enables Cron, supports adding multiple machines through governance and removes the MRSIGNER requirement. That last change makes older repository descriptions of mandatory developer-signed enclave code incomplete. A release record establishes what the published software changes; it does not independently establish the exact activation time of every operator. Keeping those two claims separate is especially important when emergency hardware policy, node admission and contract functionality change in the same package.
The June 10 v1.25.0 release adds machine-ID replacement, updates emergency validator information and introduces a beta non-SGX node that must pair with an SGX node. The pairing requirement is decisive: it is not evidence that confidential execution became independent of trusted hardware or that fully autonomous non-SGX validators were deployed. Software can make public infrastructure easier to operate while still relying on a smaller specialized execution component. Describing the architecture requires following that dependency rather than counting a new binary as a new security model.
The June exploit was a bridge authorization failure
Common Prefix's technical postmortem traces the June 10, 2026 exploit to modified Secret-side ICS-20 logic that no longer enforced the necessary source-channel and denomination checks. An attacker used a controlled chain to create unbacked representations, then redeemed through the legitimate Axelar connection. Valid IBC proofs established that messages came from a chain; they did not establish legitimate backing for the claimed asset. The report estimates $4.67 million affected and distinguishes these bridged assets from native SCRT and unrelated Axelar escrows.
Alex Zaidelson's June 19 incident thread likewise identifies the Secret-side bridge contract and reports that the connection was paused. It contains arguments about responsibility and monitoring that should be treated as the author's position, rather than a settled judgment against every organization mentioned. The useful practical distinction is between network confidentiality, consensus and bridge accounting. A privacy-oriented chain can still host a contract with flawed asset-origin checks.
Users need the exact wrapper and channel identity before assuming one incident affects, or spares, every token with a similar ticker.
A migration headline was not a completed migration
The July 7 post titled SCRT is moving to Arbitrum explicitly made the move conditional on governance approval. It also said Labs would stop supporting the Cosmos L1 regardless of that vote, while operators could continue the existing chain. Proposed snapshot rules distinguished native and ordinarily staked SCRT from some contract positions. Those were proposed eligibility rules, not standing instructions for users to unwrap or move funds. Later community-continuance records supersede any reading of this headline as proof that the original network had already migrated.
Lisa Loud's July 28 draft proposed a different path: keep the existing L1 and include contract-held positions while funding new stewardship, infrastructure and remediation through revised economics. It explicitly identified itself as a discussion draft rather than an on-chain proposal. This was a conflict over who should be carried forward and how maintenance should be financed, as well as over technology. The possibility of changing organizations without abandoning the chain became central to the community's claim that continuity could preserve relationships a hurried migration would exclude.
Keeping the balance does not preserve the ownership share
The August 5 continuation proposal illustrated a mint of roughly 1.079 billion SCRT, leaving existing holders with about a quarter of the expanded supply while retaining their absolute balances. It allocated funds for development, infrastructure and remediation, with vesting and staking arrangements that could give allocations voting power before all principal unlocked. These are the proposal's figures and design choices, not a live supply reading.
Its explicit admission of dilution and concentration risk is essential to understanding why supporters and opponents could both favor survival yet disagree sharply about its financing.
The August upgrade coordination thread shows that the path to execution was not instantaneous. An initial schedule was delayed, followed by an August 12 announcement of an on-chain proposal and target height for v1.26.0-community-continuance. Such notices document coordination and intended activation rather than independently proving execution at the estimated hour. They also show why historical guides should preserve the status of each record: testnet success, a submitted vote, a projected block and a completed mint are different events with different evidentiary strength.
The September discussion concerns spending after the mint
In September 21 replies, Foundation representatives confirmed that the mint had occurred. Lisa Loud said there had been no core-development distributions, described validator announcements and limited infrastructure or exchange-support spending, and reiterated reporting commitments. On September 29, crypto_mentions still asked when remediation would be distributed. This establishes a post-mint continuation discussion, not a completed reimbursement program.
The replies are management representations rather than audited accounts; wallet-level reconciliation and published payment records would be needed to substantiate every category and beneficiary.
Secret's governance documentation describes bonded SCRT voting, with delegators inheriting their validator's choice unless they vote themselves. The available options include approval, rejection, veto and abstention. That mechanism explains why passive staking can carry political consequences, particularly when large allocations alter the distribution of bonded tokens. It does not make every forum poll binding or ensure that a funded organization delivers its commitments.
Parameter changes, software execution and subsequent organizational spending still require separate records, even when they originate in the same governance debate.
Cheap transactions and sustainable operations can conflict
Jiricepelka's August 24 fee discussion argues that existing minimum tiers produce too little revenue and weak resistance to spam. The post proposes higher tiers while acknowledging possible harm to application demand and IBC relayer economics. Its dollar estimates are the author's contemporary calculations, not permanent prices. By September 9 the author was still discussing a signaling proposal. The record therefore supports a debate about resource costs and sustainability, not a claim that the proposed increases had already become the network's mandatory fee schedule.
The project's Secret Finance explanation makes the original application case concrete: encrypted inputs can support lending checks and financial contracts without exposing every underlying detail. That is a reason builders may value the technology even when the network's financing is disputed. It does not make a private lending position solvent or a bridge reserve fully backed. Confidentiality governs who can inspect information; credit risk, collateral design, administrator powers and the accuracy of the input remain separate questions for each financial application.
Confidential virtual machines are an adjacent product
The February 11 SecretVM announcement introduces AMD SEV-SNP alongside Intel TDX for hosted confidential virtual machines. It describes a different workload and trust boundary from SGX-based on-chain Secret Contracts. Consequently, a product's new processor support must not be interpreted as a completed replacement of L1 execution hardware. The announcement's benchmarks are the team's internal comparisons on specified machines, not universal performance guarantees.
Its later historical banner also warns readers not to assume the organization named in the original launch still maintains the network itself.
The early network history records a community trying to make private computation useful across tokens, applications and other chains. That wider ambition helps explain why supporters see more here than a private payment coin, but it does not validate every later product under the same brand. The most informative assessment follows deployed contracts, maintained clients, explicit operator responsibilities and the status of recovery obligations. Historical bridges and application lists show what was attempted; they should not be read as a current inventory of safe or supported services.
Как мы к этому пришли.
- 2020-02-19
Enigma settlement order issued
The SEC resolves registration charges concerning the earlier ENG offering, a distinct historical asset.
- 2020-09-15
Secret Contracts launch
The community announces completion of the mainnet upgrade enabling confidential contract execution.
- 2020-10-23
secretSCRT announced
The SNIP-20 implementation introduces a private contract representation backed by native SCRT.
- 2022-10-04
Registration frozen after disclosure
The SGX.Fail detailed timeline records a response to vulnerable hardware admitting attackers; its introductory paragraph instead says October 5.
- 2026-03-30
v1.24.1 release published
The software release changes hardware admission and removes the MRSIGNER requirement.
- 2026-06-10
Bridge exploit occurs
The later technical postmortem dates the creation and redemption of unbacked Secret-side bridge tokens to this day.
- 2026-07-07
Conditional Arbitrum proposal published
Labs describes a migration dependent on approval, alongside its decision to leave L1 support.
- 2026-08-12
Continuation upgrade vote announced
The coordination thread reports submission of a v1.26.0 proposal after an earlier schedule delay.
- 2026-09-21
Foundation discusses post-mint spending
Representatives confirm the mint and respond to questions about distributions and reporting.
Убеждения, амбиции и открытые вопросы.
Это описания взглядов с указанием их авторов, а не одобрение. Откройте досье доказательств, чтобы изучить подтверждения и границы выводов.
Зафиксированное убеждениеContinue without excluding contract holders
Открыть досье доказательств
Lisa Loud argues that community stewardship can preserve the existing chain and include positions a proposed migration excluded.
Откуда взялась эта история
Her July 28, 2026 continuation draft.
Что подтверждают источники
- The draft explicitly links inclusion to new development and remediation funding.
Чего это не доказывает
- Its proposed financing was not a guarantee of viability or complete compensation.
За чем следить
- Delivered maintenance and reconciled distributions test the continuity argument.
Спорная интерпретацияA rescue also needs limits on concentrated control
Открыть досье доказательств
zenzu questions unnamed teams, liquid allocations and whether security work is adequately specified.
Откуда взялась эта история
An August 12, 2026 reply to the Secret^3 proposal.
Что подтверждают источники
- The questions challenge the governance design rather than merely rejecting privacy technology.
Чего это не доказывает
- They are a participant's concerns, not an independent audit of every allegation.
За чем следить
- Named responsibilities, published budgets and security reviews make those concerns assessable.
Спорная интерпретацияResource costs should be visible in transaction prices
Открыть досье доказательств
Jiricepelka favors higher fees to support operation and discourage abuse; Chasn welcomes a recovery effort.
Откуда взялась эта история
The August 2026 fee discussion, with replies continuing in September.
Что подтверждают источники
- The proposer also acknowledges demand and relayer-cost objections.
Чего это не доказывает
- A forum argument neither enacts fees nor proves higher prices will increase sustainable revenue.
За чем следить
- An executed decision and subsequent usage would be more informative than estimated fee income alone.
Спорная интерпретацияMigration supporters faced a demand for remediation
Открыть досье доказательств
Alex Zaidelson proposed Arbitrum migration; thenodefather wanted bridge victims addressed before that move.
Откуда взялась эта история
The July 2026 migration thread.
Что подтверждают источники
- The replies expose different priorities within the ecosystem.
Чего это не доказывает
- The proposal was conditional, and neither position proves successful recovery.
За чем следить
- Executed governance and actual compensation matter more than migration headlines.
Библиотека источников.
Первичные документы объясняют механизмы и решения. Записи сообщества показывают убеждения участников. Ниже указаны даты проверки ссылок; внешние страницы могут измениться.
- Secret Network Introduction ↗Secret Network Documentation · primary · Проверено 2026-09-30
- Secret Network Graypaper ↗Secret Network · primary · Проверено 2026-09-30
- Enigma MPC: Securities Act Release 10755 ↗US Securities and Exchange Commission · legal · Опубликовано 2020-02-19 · Проверено 2026-09-30
- Enigma MPC annual report ↗Enigma MPC / SEC EDGAR · primary · Проверено 2026-09-30
- Upgrade Complete! Secret Contracts LIVE on Mainnet ↗jlwaugh · primary · Опубликовано 2020-09-15 · Проверено 2026-09-30
- SecretSCRT: Privacy Tokens Are Live on Mainnet ↗jlwaugh · primary · Опубликовано 2020-10-23 · Проверено 2026-09-30
- Viewing Keys ↗Secret Network Documentation · primary · Проверено 2026-09-30
- Query Permits ↗Secret Network Documentation · primary · Проверено 2026-09-30
- SGX.Fail: How Stuff Gets eXposed ↗SGX.Fail research authors · primary · Проверено 2026-09-30
- Secret Network 2026 Roadmap ↗Secret Labs · primary · Опубликовано 2026-01-12 · Проверено 2026-09-30
- SecretNetwork v1.24.1 ↗Secret Labs maintainers · primary · Опубликовано 2026-03-30 · Проверено 2026-09-30
- SecretNetwork v1.25.0 ↗Secret Labs maintainers · primary · Опубликовано 2026-06-10 · Проверено 2026-09-30
- The Secret Network Exploit ↗Common Prefix · primary · Опубликовано 2026-06-19 · Проверено 2026-09-30
- Security Incident: Axelar-Secret IBC Bridge Exploit ↗Alex Zaidelson · primary · Опубликовано 2026-06-19 · Проверено 2026-09-30
- SCRT is moving to Arbitrum ↗Alex Zaidelson · primary · Опубликовано 2026-07-07 · Проверено 2026-09-30
- Community Continuance of Secret Network (L1) ↗Lisa Loud · community · Опубликовано 2026-07-28 · Проверено 2026-09-30
- Secret^3: Community Continuance of Secret Network L1 ↗Lisa Loud, zenzu and community participants · community · Опубликовано 2026-08-05 · Проверено 2026-09-30
- Upcoming Secret Network 1.26 Upgrade ↗Secret Network Foundation · primary · Опубликовано 2026-08-08 · Проверено 2026-09-30
- Request for update on Foundation fund usage ↗crypto_mentions and Foundation representatives · community · Опубликовано 2026-09-19 · Проверено 2026-09-30
- Governance ↗Secret Network Documentation · primary · Проверено 2026-09-30
- Proposal: Increase Secret Network Minimum Gas Fees ↗Jiricepelka and community participants · community · Опубликовано 2026-08-24 · Проверено 2026-09-30
- Secret Finance ↗Secret Network · primary · Проверено 2026-09-30
- SecretVM: Expanding Confidential Computing with AMD SEV-SNP ↗Ilya Raykker / Secret Labs · primary · Опубликовано 2026-02-11 · Проверено 2026-09-30
- History ↗Secret Network Documentation · primary · Проверено 2026-09-30