<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Terra_Money_IBC_Hook_Reentrancy_Vulnerability</id>
	<title>Terra Money IBC Hook Reentrancy Vulnerability - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Terra_Money_IBC_Hook_Reentrancy_Vulnerability"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Terra_Money_IBC_Hook_Reentrancy_Vulnerability&amp;action=history"/>
	<updated>2026-05-30T05:51:53Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Terra_Money_IBC_Hook_Reentrancy_Vulnerability&amp;diff=6169&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/terramoneyibchookreentrancyvulnerability.php}} {{Unattributed Sources}}  Terra Money Logo/HomepageThe Terra blockchain is a hard fork of the original Terra Luna blockchain which crashed due to a failure of the algorithmic stablecoin UST. An emergency patch was issued for a critical reentrancy vulnerability in April to all blockchains which are part of the Co...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Terra_Money_IBC_Hook_Reentrancy_Vulnerability&amp;diff=6169&amp;oldid=prev"/>
		<updated>2024-09-25T20:24:27Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/terramoneyibchookreentrancyvulnerability.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Terramoney.jpg&quot; title=&quot;File:Terramoney.jpg&quot;&gt;thumb|Terra Money Logo/Homepage&lt;/a&gt;The Terra blockchain is a hard fork of the original Terra Luna blockchain which crashed due to a failure of the algorithmic stablecoin UST. An emergency patch was issued for a critical reentrancy vulnerability in April to all blockchains which are part of the Co...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/terramoneyibchookreentrancyvulnerability.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Terramoney.jpg|thumb|Terra Money Logo/Homepage]]The Terra blockchain is a hard fork of the original Terra Luna blockchain which crashed due to a failure of the algorithmic stablecoin UST. An emergency patch was issued for a critical reentrancy vulnerability in April to all blockchains which are part of the Cosmos ecosystem. Unfortunately, Terra did not upgrade their protocol to apply the patch. It was exploited to take millions of dollars worth of assets. Some assets have been recaptured so far.&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14855&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;theblock-14894&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;terramoney-14895&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;wikipedia-14896&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;terramoneytwitter-14778&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptobriefing-14780&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;beosinalerttwitter-14781&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coindesk-14897&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;terramoneytwitter-14898&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;businessinsidermarkets-14899&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinpedia-14900&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;range-14901&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cosmosgithub-14775&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14902&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-14903&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Terra Money ==&lt;br /&gt;
&amp;quot;Terra is a blockchain protocol and payment platform used for algorithmic stablecoins. The project was created in 2018 by Terraform Labs, a startup co-founded by Do Kwon and Daniel Shin. It was best known for its Terra stablecoin and the associated LUNA reserve asset cryptocurrency.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Terra hosts a vibrant ecosystem of diverse products and services. Create a Station wallet to start exploring and interacting with an array of ecosystem applications. With Pulsar Finance, the leading Web3 portfolio tracker, you can effortlessly monitor all your tokens, DeFi positions, and NFTs across Terra and over 100 other blockchains.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Fueled by the passionate #LUNAtic community and deep developer talent pool, the Terra blockchain is built to enable the next generation of Web3 products and services. Build crypto's next killer app using Terra's suite of developer tools and resources.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Terra was hard forked from the Terra Classic network following a major financial collapse in 2022, which was triggered by its algorithmic stablecoin, UST, losing its supposed peg to the US dollar.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
&amp;quot;The vulnerability was identified a few months ago and patched across the Cosmos ecosystem in April. However, a later upgrade in June on Terra failed to include this patch, leading to renewed exposure and the subsequent exploit, Zaki Manian, co-founder of Sommelier Protocol, explained.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;This bug was known as the IBC reentrancy infinite mint bug, and all Cosmos chains issued an emergency patch to remediate this issue.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;In April 2024 theIBC-Go library issued an emergency patch for the reentrancy bug. The affected version that is relevant to Terra is &amp;lt; 7.4.0. Terra was utilizing a custom version of IBC-Go 7.3.1 at the time of the attack (github.com/terra-money/ibc-go/v7 v7.3.1-terra.0) that was vulnerable to the exploit.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Terra Money IBC Hook Reentrancy Vulnerability&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|April 5th, 2024 6:21:00 AM MDT&lt;br /&gt;
|Reentrancy Article Published&lt;br /&gt;
|&amp;quot;ASA-2024-007: Potential Reentrancy using Timeout Callbacks in ibc-hooks&amp;quot; is published which outlines the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 6:18:35 AM MDT&lt;br /&gt;
|Funds Bridged In&lt;br /&gt;
|The attacker starts to bring in funds from Ethereum to their wallet.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 5:09:11 PM MDT&lt;br /&gt;
|First Exploit Transfer&lt;br /&gt;
|The first transfer of Ethereum funds from the exploit, which are bridged in through Uniswap.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 7:39:23 PM MDT&lt;br /&gt;
|Final Exploit Transfer&lt;br /&gt;
|The final swap related to the exploit transactions.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 10:06:00 PM MDT&lt;br /&gt;
|Terra Pause Announced&lt;br /&gt;
|Terra announces a pause in the blockchain starting shortly at block #11,430,400.&lt;br /&gt;
|-&lt;br /&gt;
|July 30th, 2024 10:17:05 PM MDT&lt;br /&gt;
|Terra Blockchain Paused&lt;br /&gt;
|The terra blockchain is paused to deal with the vulnerability.&lt;br /&gt;
|-&lt;br /&gt;
|July 31st, 2024 12:20:06 AM MDT&lt;br /&gt;
|The Block Article&lt;br /&gt;
|The Block publishes an article on this incident.&lt;br /&gt;
|-&lt;br /&gt;
|July 31st, 2024 1:23:00 AM MDT&lt;br /&gt;
|Beosin Tweet Posted&lt;br /&gt;
|Beosin posts a tweet about the reentrancy vulnerability which was exploited.&lt;br /&gt;
|-&lt;br /&gt;
|July 31st, 2024 1:31:00 AM MDT&lt;br /&gt;
|Cyvers Tweet&lt;br /&gt;
|Cyvers tweets about the exploit further.&lt;br /&gt;
|-&lt;br /&gt;
|July 31st, 2024 1:40:00 AM MDT&lt;br /&gt;
|Terra Blockchain Resumed&lt;br /&gt;
|The Terra blockchain announces that it's been resumed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;In April 2024 theIBC-Go library issued an emergency patch for the reentrancy bug. The affected version that is relevant to Terra is &amp;lt; 7.4.0. Terra was utilizing a custom version of IBC-Go 7.3.1 at the time of the attack (github.com/terra-money/ibc-go/v7 v7.3.1-terra.0) that was vulnerable to the exploit.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;According to Zaki Manian, co-founder of Sommelier Finance, although the vulnerability was patched in the Cosmos ecosystem back in April, Terra did not include this patch in their June upgrade, resulting in the vulnerability being re-exposed and exploited.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Terra blockchain experienced a security breach that led to the theft of tokens. The attackers exploited a known vulnerability related to the third-party module IBC hooks, stealing the value of cross-chain assets, including USDC stablecoins and Astroport tokens. The Terra team has taken emergency measures to prevent further losses and coordinated with validators to apply a patch to fix the vulnerability.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;“There was a vulnerability in IBC hooks discovered by Composable Finance in April. It was patched across Cosmos. Terra was patched then,” Manian told The Block. “It appears that Terra's June upgrade did not include the patch. All the Axelar USDC bridged to Terra was stolen using the IBC hooks exploit. A large amount of ASTRO was also stolen.&amp;quot;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $5,280,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;Attention Terra users: Please be advised that the chain will be halted shortly at block height 11430400 and transactions will not be processed during this time.&lt;br /&gt;
&lt;br /&gt;
We will be working with the validators on Terra (phoenix-1) to apply an emergency patch thereafter to remediate a suspected exploit.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;The Terra chain has resumed block production at approximately 4:19 AM UTC today and the emergency chain upgrade is now complete.&lt;br /&gt;
&lt;br /&gt;
Transactions are now being processed, and users may resume normal activities.&lt;br /&gt;
&lt;br /&gt;
Validators holding over 67% of the voting power on Terra have upgraded their nodes to prevent the exploit from recurring. More validators are expected to upgrade soon.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;After these events, both the Terra and Astroport teams took swift action to lessen the impact of the attack. The Terra team upgraded the IBC-Go version appropriately and also introduced a new blacklist antehandler. This will effectively add a step to the transaction pre-processing to see if the transaction signer is on a list of blacklisted addresses, and if so, it will block the transaction. It is important to note that this blacklist only has one address, and it is the ibc-exploiter’s terra address that is holding around $650,000 USD in stolen funds, mainly consisting of 20,000,000 ASTRO. These funds are now locked and are out of circulation.&lt;br /&gt;
&lt;br /&gt;
The Astroport team was able to seize the ASTRO in the attacker's Neutron wallet because ASTRO recently migrated from a cw20 Terra token to a tokenfactory denom on Neutron. This gives the token admin unique privileges to recover the funds. This was accomplished through a force transfer from the attacker's Neutron wallet. It should be noted that this action was only possible on the origin chain of the Astro token (Neutron in this case) and would not have been possible if the token versions were wrapped.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The total amount recovered is unknown.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisthackedarchive-14855&amp;quot;&amp;gt;[https://web.archive.org/web/20240808214412/https://hacked.slowmist.io/ SlowMist Hacked - SlowMist Zone] (Accessed Aug 8, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;theblock-14894&amp;quot;&amp;gt;[https://www.theblock.co/post/308440/attacker-exploits-ibc-hooks-vulnerability-to-steal-tokens-on-terra-blockchain https://www.theblock.co/post/308440/attacker-exploits-ibc-hooks-vulnerability-to-steal-tokens-on-terra-blockchain] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;terramoney-14895&amp;quot;&amp;gt;[https://www.terra.money/ Terra] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;wikipedia-14896&amp;quot;&amp;gt;[https://en.wikipedia.org/wiki/Terra_(blockchain) Terra (blockchain) - Wikipedia] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;terramoneytwitter-14778&amp;quot;&amp;gt;[https://twitter.com/terra_money/status/1818498438759411964 @terra_money Twitter] (Accessed Aug 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptobriefing-14780&amp;quot;&amp;gt;[https://cryptobriefing.com/terra-blockchain-exploit-6m/ Terra hit by $6 million loss as attacker exploits vulnerability known since April] (Accessed Aug 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;beosinalerttwitter-14781&amp;quot;&amp;gt;[https://twitter.com/BeosinAlert/status/1818548029416411279 @BeosinAlert Twitter] (Accessed Aug 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coindesk-14897&amp;quot;&amp;gt;[https://www.coindesk.com/tech/2024/07/31/terra-blockchain-restarts-after-4m-exploit/ Terra Blockchain Restarts After Reentrancy Attack Leads to $4M Exploit] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;terramoneytwitter-14898&amp;quot;&amp;gt;[https://twitter.com/terra_money/status/1818552290372206614 @terra_money Twitter] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;businessinsidermarkets-14899&amp;quot;&amp;gt;[https://markets.businessinsider.com/news/currencies/terra-blockchain-restarts-after-4m-exploit-1033617551 Terra Blockchain Restarts After $4M Exploit | Currency News |  Financial and Business News | Markets Insider] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinpedia-14900&amp;quot;&amp;gt;[https://coinpedia.org/news/terra-blockchain-hack-6-8-million-stolen-astro-plummets-60/ Terra Blockchain Hack: $6.8 Million Stolen, ASTRO Plummets 60%] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;range-14901&amp;quot;&amp;gt;[https://www.range.org/blog/terra-ibc-hooks-exploit-analysis Terra IBC Hooks Exploit Analysis - Range Security] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cosmosgithub-14775&amp;quot;&amp;gt;[https://github.com/cosmos/ibc-go/security/advisories/GHSA-j496-crgh-34mx ASA-2024-007: Potential Reentrancy using Timeout Callbacks in ibc-hooks · Advisory · cosmos/ibc-go · GitHub] (Accessed Aug 6, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14902&amp;quot;&amp;gt;[https://etherscan.io/tx/0xf1c7e570dd6fa6341a466b6497d640307fa6560386b2b7fb744b788bf114b16e Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;etherscan-14903&amp;quot;&amp;gt;[https://etherscan.io/tx/0x6677ba277427c0d3ecfcd65b75033637eac42912c81945c67b9e6b471212b4ca Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Aug 12, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>