Terra’s blockchain was briefly halted after an attacker exploited an IBC hooks vulnerability to steal tokens, with the incident traced to a flaw that had been identified and patched across parts of the Cosmos ecosystem in April. Reporting and security analysis indicate the exploit drained a mix of assets including Axelar USDC, USDT, BTC, and ASTRO, with the total loss estimated at just over $4 million at the time of the attack. The core issue involved IBC hooks, a middleware that lets ICS-20 transfers trigger contract calls through packet memos. According to security researchers, the relevant bug was a reentrancy-style weakness in ibc-go that could allow repeated refund or mint-like behavior during timeout handling; Terra had previously used a vulnerable custom ibc-go version, and one report says Terra developers missed including the fix in a recent June upgrade before the exploit occurred. The chain was paused for about four hours while validators deployed an emergency patch, and block production later resumed after the fix was applied. The incident matters because it shows how a known Cosmos IBC vulnerability could still affect a live chain if an upgrade omits the remediation, and it underscores the security risk created by composable cross-chain middleware. The broader concern is not just the direct loss on Terra, but the fact that the same flaw was described by researchers as capable of affecting other IBC-enabled chains if not fully patched.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Exploit

Comments