Terra Classic Proposes $90,800 Security Audit by SolidProof and OrbitLabs
Terra Classic is facing a major security review proposal that would fund a comprehensive blockchain audit by SolidProof and remediation work by OrbitLabs, with a total planned cost of $90,800 in LUNC.
The proposal seeks to examine the current Terra Classic codebase, identify potential security vulnerabilities, test critical protocol components under adversarial conditions, and verify that reported issues are properly fixed.
The proposed audit comes after significant changes to the Terra Classic blockchain in recent years, including its migration to newer Cosmos SDK infrastructure. The Terra Classic core repository confirms that the chain completed its Cosmos SDK 0.53 upgrade in 2026, while subsequent releases have introduced additional protocol and security changes.
Terra Classic Security Audit Proposal
The proposal calls for SolidProof, a German blockchain security company, to conduct a comprehensive security assessment of Terra Classic.
The audit would not only review the existing code but also include a re audit after identified vulnerabilities are remediated. A final report would then document the status of each finding and the effectiveness of the fixes.
According to the proposal, the audit is expected to take approximately 6.5 weeks, followed by an estimated four week remediation period. The final audit report is expected within approximately 10 weeks of the process beginning.
The proposal states that the audit would begin approximately three weeks after approval.
Why Terra Classic Wants a New Audit
The proposal points to the age of Terra Classic’s previous security audit as one of the main reasons for the review.
According to the proposal, the last audit was conducted before the September 2020 crash. Since then, Terra Classic has undergone substantial technical changes, including updates to its Cosmos SDK infrastructure, IBC integration, CosmWasm environment and custom modules.
The current Terra Classic codebase reflects these changes. Its 2026 v4.0.0 release introduced the Cosmos SDK 0.53 upgrade, with CometBFT, wasmd and wasmvm also updated as part of the migration.
The proposal also cites security incidents affecting other blockchain networks as part of the broader security environment.
It further states that partner exchanges listing LUNC and USTC have indicated that a security audit is important following security breaches affecting other Cosmos based networks.
What SolidProof Would Review
The proposed audit covers a broad portion of the Terra Classic protocol.
SolidProof would examine the source code for the Terra Classic protocol, with particular attention to its custom modules, Cosmos SDK overrides, transaction processing, fee handling, application and IBC configuration, and CosmWasm integration.
The review would also examine the migration framework introduced during the Cosmos SDK 0.53 upgrade.
This includes all 20 upgrade handlers and the manually developed CosmWasm key value store migration that was executed on Terra Classic mainnet.
The economic mechanisms of the blockchain would also be assessed.
These include oracle voting and rewards, treasury seigniorage, burn tax collection and exemptions, and dynamic validator commission enforcement.
Adversarial Security Testing
The proposal goes beyond a traditional source code review.
SolidProof would also perform adversarial testing using fuzzing, localnet testing and interchain scenarios.
The testing would examine potential scenarios including oracle manipulation, burn tax bypasses, treasury drains and denial of service attacks.
The audit would also evaluate how Terra Classic behaves when multiple validators act maliciously or when critical components are exposed to unexpected transaction and interchain conditions.
This approach is designed to identify vulnerabilities that may not be visible through manual source code review alone.
Eight Core Areas of the Audit
The proposed scope is divided into eight major areas.
A. Custom Module Implementation
The review would cover Terra Classic’s custom modules, including the oracle, treasury, market, tax, tax exemption, dynamic commission and vesting modules.
The oracle module review would examine vote handling, weighted median calculations, reward distribution, missed votes and slashing.
The treasury review would cover seigniorage calculations, tax and reward policies, burn account operations and governance proposal handling.
The market module would also be reviewed for swap behaviour, liquidity pool calculations, stability spread application and oracle price integration where applicable.
B. Transaction Processing and Fees
The audit would examine how transactions move through Terra Classic’s custom processing system.
This includes authentication, gas metering, fee deduction, burn tax calculations and the interaction between these systems.
Special attention would be given to rounding, truncation, precision loss and fee grant interactions.
The review would also examine spam prevention mechanisms for oracle voting and IBC transfers.
C. Framework Migration and State Integrity
The CosmWasm store migration introduced during the Cosmos SDK upgrade would receive specific attention.
Auditors would examine contract keys, code keys, storage keys, contract history, indexes, sequence keys and parameters.
The review would also investigate whether migration logic remains deterministic and whether historical state can be reliably accessed after the migration.
All 20 upgrade handlers would be reviewed, including their declared store upgrades, idempotency and parameter handling.
D. Cosmos SDK Override Layer
Terra Classic maintains several custom overrides and compatibility components on top of the Cosmos SDK.
The audit would examine all 13 module overrides, including areas involving wasm, staking, bank and governance.
It would also review module ordering, module account permissions, blocked addresses and authority addresses for parameter updates.
E. CosmWasm Integration
The review would examine the chain’s interaction with CosmWasm smart contracts.
Areas include custom query and message plugins, Stargate query permissions, deterministic responses, reentrancy, state consistency and gas accounting.
The migration from older wasmd and wasmvm versions to the current versions would also be assessed.
F. IBC Integration
The audit would examine Terra Classic’s IBC implementation and middleware structure.
This includes packet, acknowledgement and timeout handling, the integration of IBC hooks, interchain accounts and wasm, as well as changes associated with the ibc go migration.
The auditors would also assess whether certain packet paths can be reached under the current application router configuration.
G. Node Availability and API Surface
The custom FIFO mempool would be reviewed for eviction, ordering and transaction processing behaviour.
The audit would also examine the custom HTTP middleware, including transaction log reconstruction and potential resource allocation issues.
Default node configuration and security hardening would form part of this review.
H. Economic Mechanisms
Economic security would be another major focus.
The audit would examine oracle manipulation resistance, vote buying, Sybil resistance, burn tax bypasses, exemption abuse, treasury drain scenarios and seigniorage manipulation.
Denial of service scenarios targeting custom modules and the mempool would also be tested.
Where the market swap mechanism is enabled by current on chain parameters, the auditors would examine market manipulation and arbitrage scenarios.
OrbitLabs Would Handle the Fixes
If vulnerabilities are identified, OrbitLabs would be responsible for implementing the required fixes.
OrbitLabs has previously contributed to Terra Classic’s Cosmos SDK 0.53 upgrade. The Terra Classic repository records the SDK 0.53 upgrade as part of the v4.0.0 development.
Under the new proposal, OrbitLabs would work directly with SolidProof during the remediation process.
The development team would prepare fixes for identified vulnerabilities and, where necessary, prepare a chain upgrade proposal to implement consensus relevant changes.
The proposed fixed price for this work is $20,000 in LUNC.
OrbitLabs estimates approximately 10 days for development work and another six days for preparing the upgrade proposal.
Audit Includes Re Audit of Fixes
One of the significant elements of the proposal is that the process would not end after vulnerabilities are identified.
SolidProof would conduct a full re audit of the remediation work.
Each reported issue would receive a status indicating whether the fix was verified, partially verified or ineffective.
The final audit report would then document the results.
This creates a process covering identification, remediation and verification rather than simply publishing a list of vulnerabilities.
Proposed Audit Deliverables
The proposal outlines several deliverables from SolidProof.
These include a threat model and architecture assessment, an interim findings report, a draft audit report and a final publishable audit report.
The final report would include the affected code paths, severity classifications, potential impact, reproduction information where possible and remediation recommendations.
The proposal also calls for a recommendation summary separating fixes that require a consensus changing governance upgrade from fixes that can be implemented without breaking consensus.
Another proposed deliverable is hardened continuous integration configuration.
The proposal specifically notes that the current configuration disables several security relevant Go linters, including errcheck, staticcheck, revive and unparam.
A pull request would be provided to enable the relevant security checks and address existing violations.
$70,800 Audit Cost Plus $20,000 for Fixes
The SolidProof audit itself is priced at a fixed $70,800.
The proposal states that SolidProof has quoted 472 hours of audit work and will not charge additional fees if more work is required to deliver the agreed scope.
The community would pay SolidProof directly in LUNC.
A 20 percent buffer would also be included in the community spend proposal to account for transfer costs and LUNC price volatility during the seven day voting period.
That would bring the proposed SolidProof community spend to $84,960, with any unused buffer returned to the community pool.
OrbitLabs would separately receive $20,000 in LUNC after completing its remediation work.
This brings the total planned cost of the audit and implementation work to $90,800.
The proposal currently describes this as approximately 21.1 percent of the LUNC held in the community pool and approximately 12.2 percent of the total community pool balance based on the figures provided in the proposal.
Current Community Pool Figures
At the time the proposal was prepared, it stated that the Terra Classic community pool was worth approximately $747,000.
The proposal breaks this figure down into approximately $431,000 in LUNC and $316,000 in USTC.
The proposed $90,800 expenditure would therefore represent a significant portion of the LUNC component of the community pool, according to the proposal’s calculations.
The final amount of LUNC required for payment would also depend on the token’s price and the amount needed to cover transaction related costs during the voting period.
Terra Classic’s Recent Security Work
The proposed audit comes shortly after Terra Classic completed another security focused software upgrade.
The official Terra Classic repository describes v4.0.1 patch.3 as a mandatory security release addressing a critical vulnerability affecting wasmd and wasmvm. The release was scheduled for activation at block height 30,544,730 ahead of the public disclosure of the vulnerability.
That recent upgrade highlights the importance of maintaining security across Terra Classic’s evolving software stack.
The proposed SolidProof review would take a broader approach by examining the custom protocol implementation, economic mechanisms, migration logic, IBC integration and other components across the chain.
What Happens If the Proposal Passes
If approved, the audit process would begin approximately three weeks after the proposal passes.
SolidProof would then conduct the security review over an estimated 6.5 week period.
Identified vulnerabilities would be provided to the relevant development team for remediation. OrbitLabs would work on the fixes and prepare any required chain upgrade proposal.
SolidProof would subsequently review the implemented fixes before producing the final audit report.
The complete process is expected to take approximately 10 weeks.
Why the Proposal Matters for LUNC
Terra Classic has continued to evolve technically since its earlier architecture and security reviews.
The chain has introduced major software upgrades, including the Cosmos SDK 0.53 migration, updated CosmWasm infrastructure, IBC changes and additional custom compatibility layers.
The proposed audit would therefore provide an independent examination of the current codebase rather than relying on security assessments conducted under an older version of the network.
At the same time, the proposal represents a substantial community expenditure of $90,800 in LUNC.
The decision ultimately rests with Terra Classic governance and community participants, who will assess the proposed security benefits, scope, costs and use of community pool funds.
The proposal is currently listed among the active Terra Classic governance discussions, where the full scope and terms can be reviewed.
