How a Previously-Patched IBC Flaw Cost Astroport $6.4M on Terra
On July 30, Astroport, a decentralized exchange running on the Terra blockchain, suffered an exploit that drained roughly $6.4 million in assets. The root cause was a vulnerability that had already been identified and fixed back in April, only to be unintentionally reintroduced during a subsequent June upgrade.
The episode invites scrutiny of security practices across the Terra ecosystem, particularly given the timing alongside the SEC's enforcement actions against Terraform Labs (TFL), which restricted the company's US operations earlier in the year.

Credit for surfacing and documenting the incident goes to Rarma, Cyvers, Astroport, Terra, Jacob Gadikian, gabrielShapir0, Zaki Manian, and FXStreet.
Terra — the network that relaunched as Terra 2.0 following the collapse of its original algorithmic stablecoin — has now shown that legacy issues can resurface even after a fresh start.
Community member Rarma first flagged the incident after spotting millions of dollars moving through suspicious transactions. Astroport confirmed the exploit shortly afterward, and Terra's validators responded by halting the chain to contain the damage.
The underlying issue traces back to a critical IBC vulnerability that had been patched across Cosmos-based chains in an April emergency fix. That patch was accidentally undone during Terra's June network upgrade, leaving the flaw exposed once again. The attacker took advantage of a reentrancy bug in the timeout callback of the ibc-hooks module, using it to mint tokens without any backing.
In total, the exploiter generated 60 million ASTRO tokens along with 3.5 million USDC, 500,000 USDT, and 2.7 BTC — a haul valued at approximately $6.4 million at the time.
About 3.5 hours after the halt, Terra resumed normal operation following deployment of an emergency chain upgrade. More than 67% of Terra's voting power had upgraded validator nodes to close the hole, with additional validators expected to follow suit.
Astroport later reported that it had frozen the attacker's Terra wallet, which still held 20 million ASTRO, leaving that portion of the loot inaccessible.
Of the 58 million ASTRO tokens taken in total, 33 million were bridged to Neutron, where they were clawed back from the exploiter's wallet via a TokenFactory Force Transfer. The remaining 20 million ASTRO still sitting on Terra were blacklisted. In the aftermath, ASTRO's market price fell by roughly 56%, per Coingecko.
Attacker's address on Terra: terra1wrve5z5vsmrgy6ldcveq93aldr6wk3qmxavs4j
Attacker's address on Neutron: neutron16wynag7xgfy35sp8c5ls25c0je7dydmvq5pnd8
A portion of the funds was also bridged to Ethereum and converted into ETH.
Bridge transaction: 7E28A2BDD3A6DBED27269C23D0BDA2FBE4B2BE7F613E87CC23A237DA473F14E2
Ethereum address: 0xBDe173c4C2249d3a98cD6ed844a4421728114F5A
Adding to the frustration around this incident is the fact that the vulnerability had already been flagged in advance by Jacob Gadikian, a former prominent contributor to the Cosmos ecosystem. Gadikian had recently warned about the risk, but the warnings were largely dismissed by those positioned to act on them.
"This is why I stopped: coordinated harassment endured while making security reports," Gadikian said after the hack.

He had even proposed a fix beforehand: "When there's a security patch in comet, IBC, cosmos, etc, that shows in go.mod and that is why I automated it. This PR changes two files, go.mod and go.sum." Gadikian added: "If amulet were doing what I did, this would not have happened. It is trivial to set up monitoring for all cosmos chains based on go.mod. I know, cause I did."
His experience raises pointed questions about how the ecosystem handles security disclosures and treats those who raise them — though, as with most disputes inside the intricate and often contentious IBC community, there are likely multiple sides to the story.
Compounding the issue, Terra's development team appears to have been stretched thin. As gabrielShapir0 pointed out, Terra/TFL patched the vulnerability back in April but accidentally reverted that fix in a later update — a lapse that may be linked to TFL operating with a reduced team following the SEC's action. Zaki Manian confirmed as much: "Terra was part of the original vulnerability coordination but they accidentally reverted the patch in the June upgrade." The exploit's success may therefore be partly attributable to Terra's diminished capacity in the wake of the SEC's case against Terraform Labs.
gabrielShapir0 summarized the chain of events bluntly: the SEC shuts down TFL, no one is left to patch a known Terra vulnerability, and someone mints unlimited ASTRO before dumping it.
What's left is a tangled record of patches undone, warnings unheeded, and regulatory fallout rippling through the ecosystem — a reminder that Terra's rebirth carried forward more than just its old name.
This exploit looks avoidable in hindsight, and responsibility appears spread across several parties: developers who reverted a known fix, warnings that went unheeded, and a regulatory action that left the project short-staffed. Together, these factors point to a systemic weakness in how the ecosystem approaches security. The IBC community now faces a choice — continue down the path of reactive patching and blame, or commit to proactive security and genuine collaboration.
Get new scam files the moment we publish them — usually 2–3 emails a week.