QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$6 400 000 USD
JULY 2024
GLOBAL
ASTROPORT
DESCRIPTION OF EVENTS
"Astroport. The future of trading" "Written from scratch in Rust, Astroport combines the best pieces of six years of development on the Ethereum blockchain and delivers it on multiple blockchains with a unique hub and outpost model." "Astroport is the central space station of the DeFi solar system, where travelers throughout the galaxy meet to exchange assets in a neutral marketplace. The philosophy behind Astroport is simple:
Enabling decentralized, non-custodial liquidity and price discovery for any crypto asset.
Astroport prioritizes flexibility, combining various specialized pool types and routing seamlessly across them."
"Astroport's vision is to become the prevailing next-generation AMM with deep liquidity pools and significant trading volumes for the Cosmos ecosystem. Better pricing will allow Astroport to attract more liquidity, leading to a self-reinforcing loop."
"The essential primitive within any DeFi ecosystem is the asset exchange functionality. Automated Market Makers (AMMs) like Astroport enable swaps in a decentralized, non-custodial, way.
With Astroport, liquidity providers (LPs) can choose different pool types within a single and effective AMM system. Thus, anyone can onboard and trade tokens in a permissionless way. Moreover, no captain or bureaucrat can stop them, as the station is owned solely by its users."
"Through the deployment and subsequent use of a malicious CosmWasm contract via IBC interactions, an attacker could potentially execute the same MsgTimeout inside the IBC hook for the OnTimeout callback before the packet commitment is deleted. On chains where ibc-hooks wraps ICS-20, this vulnerability may allow for the logic of the OnTimeout callback of the transfer application to be recursively executed, leading to a condition that may present the opportunity for the loss of funds from the escrow account or unexpected minting of tokens."
"According to Beosin, the attacker exploited a reentrancy vulnerability related to the interoperability function of the Cosmos ecosystem called Inter-Blockchain Communication (IBC), which was disclosed in April this year."
"Actively looking into WHAT is happening. The wallet never receives morre than56 LUNA and 7.8k USDC and leaves with MILLIONS.
A contract is instantiated on Terra, which is then called with an IBC transfer that times out, and tokens arrive in the account, which then get IBC transferred out.
"Attention Terra users: Please be advised that the chain will be halted shortly at block height 11430400 and transactions will not be processed during this time.
We will be working with the validators on Terra (phoenix-1) to apply an emergency patch thereafter to remediate a suspected exploit."
"Terra chain has halted for emergency upgrades.
It appears an IBC vulnerability was exploited in order to mint several tokens on Terra chain, including $ASTRO. As the chain has now halted, no further tokens are able to be minted at this time.
The Astroport contributors are working with the other chains and Cosmos builders to determine what measures can be taken. We will keep you updated as we learn more."
"The price of the token ASTRO, native to the decentralized exchange Astroport, slumped up to 71% following the exploit news. Meanwhile, the price of the token LUNA remained relatively steady, falling 3% in the past 24 hours. The total value locked at Terra also took a hit after the exploit, shrinking by 15%."
Astroport is a decentralized finance (DeFi) platform built in Rust that operates across multiple blockchains, aiming to be a central hub for asset exchanges in the Cosmos ecosystem. It provides a flexible Automated Market Maker (AMM) system with various specialized pools, enabling decentralized, non-custodial liquidity and price discovery for any crypto asset. Recently, a vulnerability in the Inter-Blockchain Communication (IBC) protocol was exploited, leading to a major security breach. The exploit involved a reentrancy issue allowing malicious actors to execute unauthorized transactions, resulting in the minting of additional tokens, including $ASTRO, and significant financial losses. In response, the Terra blockchain has halted operations to implement emergency fixes. The price of the ASTRO token dropped sharply by up to 71%, while LUNA's price fell slightly by 3%. The total value locked on Terra also decreased by 15% following the incident.
Rekt - Astroport - Rekt (Aug 6)
@Rarma_ Twitter (Aug 6)
Mintscan (Aug 6)
Ethereum Transaction Hash (Txhash) Details | Etherscan
(Aug 6)
Mintscan (Aug 6)
ASA-2024-007: Potential Reentrancy using Timeout Callbacks in ibc-hooks · Advisory · cosmos/ibc-go · GitHub (Aug 6)
@TobyFrei4 Twitter (Aug 6)
@astroport_fi Twitter (Aug 6)
@terra_money Twitter (Aug 6)
Mintscan (Aug 6)
Terra hit by $6 million loss as attacker exploits vulnerability known since April (Aug 6)
@BeosinAlert Twitter (Aug 6)
Astroport. The future of trading. (Aug 6)
Astroport Docs (Aug 6)
Astroport Onboarding | Astroport Docs (Aug 6)
The Impact | Astroport Docs (Aug 6)
The Vision | Astroport Docs (Aug 6)
Launching the Astroport brand into the creative commons (Aug 6)