The Terra blockchain experienced a security breach, leading to the unauthorised theft of millions of tokens.
A vulnerability within the IBC hooks, a third-party module essential for cross-chain contract calls and token movements, was exploited.
The breach resulted in the illicit transfer of assets, including USDC stablecoin and Astroport tokens, totalling approximately $5.28 million.
Emergency Measures Taken
In response, Terra swiftly deployed an emergency patch to address the exploit and bolster security.
A statement from Terra confirmed collaboration with network validators to implement the patch and prevent future attacks.
This vulnerability had been identified and patched across the Cosmos ecosystem in April, but a subsequent Terra upgrade in June failed to include this critical fix, leaving the network exposed.
Details of the Exploit
The breach led to the theft of 60 million ASTRO, 3.5 million USDC, 500,000 USDT, and 2.7 BTC, as reported by smart contract audit firm Beosin.
Zaki Manian, co-founder of Sommelier Finance, explained that the vulnerability in IBC hooks was known and addressed, but Terra's June upgrade overlooked this patch.
All Axelar USDC bridged to Terra was stolen, along with a significant amount of ASTRO.
Terra has resumed block production
Terra was hard forked from the Terra Classic network after a financial collapse in 2022, triggered by the algorithmic stablecoin UST losing its peg to the US dollar.
Despite the breach, Terra has resumed block production.
Market Recovery and Ongoing Threats
The cryptocurrency market demonstrated resilience, recovering 77% of stolen funds in Q2 2024, with $347.4 million recovered or frozen from a total loss of $512.9 million, according to Hacken's Web3 Security Report.
The report highlighted the prevalence of scams on the platform X, where scammers have been exploiting account impersonation, leading to nearly $50 million in monthly losses.
Binance co-founder Yi He recently raised concerns about the surge in cryptocurrency scams on X, questioning the platform's response.