Post Mortem: TerraPort Finance

研究与成果 安全事件分析
Post Mortem:  TerraPort Finance

Project name: TerraPort Finance

Project type: DEX

Date of exploit: Apr 10th, 2023

Asset loss: around $4M

Vulnerability: Centralization Related Risk

Date of audit report publishing: Dec 11th, 2023

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Terraport operates as a DeFi platform that uses smart contracts on the Terra Classic blockchain. It is structured around a circular economy model designed for perpetual self-sustainability. The platform's operations are driven by its inherent deflationary token, $TERRA, which serves as a key to unlocking different functionalities within the ecosystem.

Nature of the Vulnerability

The Terraport Liquidity wallet is breached due to potential centralization risk.

CertiK Audit Overview

Screenshot 2024-01-11 at 8.44.16 PM

Conclusion

On April 10th, 2023, the Terraport project team was alarmed breach detected with the Terraport Liquidity wallet. The total loss is around $4M.

CertiK performed the audit assignment after the exploit.

References

https://twitter.com/_Terraport_/status/1645330062378508289

相关博客

Post Mortem: Thoreum Finance

Post Mortem: Thoreum Finance

On Jan 18, 2023, Thoreum Finance's token contract v4 was exploited, leading to a loss of around 2,260 WBNB. The attacker took advantage of the flawed implementation in the token contract's transfer function and manipulated its balance.

Post Mortem: Telcoin

Post Mortem: Telcoin

​​On Dec 26th, 2023, Telcoin experienced a loss of ~$1.25M attack. The vulnerable contract is due to a vulnerability in the proxy implementation of wallet contracts, which is a different application from what CertiK has audited.

Post Mortem: Sushiswap

Post Mortem: Sushiswap

On April 9th, 2023, the RouteProcessor2 in Sushiswap was exploited due to missing validation on the input with processRoute function. The total loss is around $ 3.3 M.