Terra resumes operations after $5M security breach triggers Astroport token plunge

10 months ago

The Terra blockchain has resumed mean operations aft the web implemented a impermanent halt to halt a caller exploit.

Earlier today, Terra reported a information breach that led to the theft of assorted assets, including USDC and Astroport tokens.

The attack

The exploit targeted a vulnerability successful IBC-hooks, a third-party add-on for Inter-Blockchain Communication (IBC) that supports cross-chain declaration interactions and token transfers. Although Terra patched the contented successful April, the hole was unintentionally reversed successful a June update.

Cyvers Alert, a Web3 information firm, explained that the attacker exploited a reentrancy vulnerability successful the timeout callback of IBC hooks.

The steadfast revealed that the attacker utilized this vulnerability to bargain assets worthy astir $5 million. This includes 60 cardinal ASTRO valued astatine astir $1 million, 3.5 cardinal USDC, 500,000 USDT, and 2.7 BTC, astir $178,000 astatine existent rates.

In response, the web paused artifact accumulation astatine artifact tallness 11,430,400 to instrumentality an exigency patch.

The vulnerability has been fixed arsenic of property time, and the web Validators are updating their nodes to forestall akin exploits. Terra added:

“Validators holding implicit 67% of the voting powerfulness connected Terra person upgraded their nodes to forestall the exploit from recurring. More validators are expected to upgrade soon.”

Astroport token declines

Despite Terra’s betterment efforts, Astroport’s ASTRO token has plunged by 62% successful the past 24 hours, trading astatine $0.01775, according to CryptoSlate’s data.

The Cosmos-based liquidity protocol explained that the IBC vulnerability allowed the attacker to mint respective tokens connected the Terra chain, negatively impacting the asset’s price. It stated:

“The Astroport contributors are moving with the different chains and Cosmos builders to find what measures tin beryllium taken. We volition support you updated arsenic we larn more.”

Meanwhile, information experts person besides emphasized that Astroport wasn’t exploited, and its token “became collateral harm due to the fact that it’s the lone Terra token that has meaningful liquidity for stealing.”

The station Terra resumes operations aft $5M information breach triggers Astroport token plunge appeared archetypal connected CryptoSlate.

View source