Terra Classic’s $70,800 Security Audit Payment Plan Sparks Governance Debate
Terra Classic is facing a major governance decision over blockchain security, but the biggest debate may not be about the audit itself.
The focus is increasingly shifting to how the community pool should pay for it.
Proposal #12228, titled “Proposal: Terra Classic Security Audit by SolidProof & fixes by OrbitLabs,” proposes a comprehensive security audit by SolidProof, followed by remediation work from OrbitLabs.
SolidProof has quoted a fixed $70,800 USD for the audit, re audit of remediated findings and final report. However, the proposal specifies that the SolidProof payment would be made upfront in LUNC to a Terra Classic address controlled by SolidProof.
A separate $20,000 USD allocation is proposed for OrbitLabs to implement fixes and prepare the required software upgrade proposal, with that payment scheduled after the work is completed. A 20% buffer is also requested for the SolidProof payment to account for LUNC price volatility and transfer costs, with unused funds intended to return to the community pool.
That structure has opened a wider discussion among LUNC holders about treasury protection, payment milestones and how blockchain security work should be funded through governance.
What Is Terra Classic Proposal #12228?
The proposal aims to conduct a comprehensive security assessment of the current Terra Classic blockchain.
According to the proposal, the last cited audit of the chain took place before the September 2020 crash. Since then, Terra Classic has undergone substantial technical changes, including upgrades to its Cosmos SDK infrastructure and other components.
The proposed audit would therefore examine the current codebase rather than relying on an older security assessment.
| Stage | Provider | Proposed Cost | Payment Structure |
|---|---|---|---|
| Security audit and re audit | SolidProof | $70,800 | Upfront |
| Payment buffer | Community pool | 20% buffer | Unused amount returned |
| Vulnerability fixes | OrbitLabs | $20,000 | After completion |
| Total core cost | SolidProof + OrbitLabs | $90,800 | Mixed structure |
The proposal states that the SolidProof audit fee is fixed at $70,800 for the agreed scope. SolidProof estimates approximately 472 hours of work for the audit.
Why Does Terra Classic Need Another Security Audit?
The main argument behind the proposal is that Terra Classic has changed significantly since its previous audit.
The proposed review covers several critical components of the blockchain, including custom Terra Classic modules, Cosmos SDK modifications, transaction processing, fee calculations, CosmWasm integration, IBC functionality and state migrations.
The scope also includes security testing against potential attack scenarios.
These include areas such as:
- Oracle manipulation
- Burn tax bypass
- Treasury drain attempts
- Denial of service
- Transaction and fee processing issues
- Problems involving blockchain state migrations
The objective is to identify vulnerabilities in the current chain and provide recommendations before those vulnerabilities can create larger risks.
The Cosmos SDK 0.53 Migration Is Part of the Review
Another important part of the proposed audit is Terra Classic’s migration to Cosmos SDK 0.53.
The proposal specifically includes review of the upgrade handlers and the manually implemented CosmWasm key value store migration used during the mainnet upgrade.
This is significant because blockchain migrations can affect state integrity, determinism and compatibility.
A security review of these areas could therefore examine whether the current implementation behaves as expected after the major framework changes.
What Happens If SolidProof Finds Vulnerabilities?
The proposal does not end with the audit report.
If vulnerabilities are identified, OrbitLabs would be responsible for implementing the necessary fixes.
OrbitLabs previously worked on the Terra Classic Cosmos SDK 0.53 upgrade and would be responsible for developing remediation work and preparing the required software upgrade proposal.
The proposed process is:
Security audit → Vulnerability fixes → Re audit → Final report
The proposal allocates $20,000 USD in LUNC for the OrbitLabs remediation work, with payment scheduled after the work is completed.
This means the proposal separates the security assessment from the development work required to address its findings.
The $70,800 Upfront Payment Is the Main Point of Debate
The most important financial detail is straightforward.
SolidProof would receive its $70,800 audit fee upfront.
The payment would be made in LUNC directly to a Terra Classic address owned by SolidProof, according to the proposal.
The proposal also requests an additional 20% buffer to protect against LUNC price movements and transfer costs during the governance process.
If the full buffer were applied to the $70,800 audit fee, the amount allocated for the initial SolidProof payment would be $84,960.
The proposal says any unused portion of the buffer would be returned to the community pool.
This creates a different payment structure from the proposed OrbitLabs arrangement.
For SolidProof:
Payment first → Audit → Remediation → Re audit → Final report
For OrbitLabs:
Work → Completion → Payment
That difference is at the center of the treasury discussion.
Why Does the Payment Structure Matter?
An upfront payment does not by itself establish that a service will fail to deliver.
However, it changes the financial relationship between the community and the service provider.
When payment is made after milestones are completed, the payer retains some financial leverage throughout the project.
When payment is made upfront, that leverage is reduced because the majority of the contracted fee has already been transferred.
For a community funded treasury, that makes the agreement, scope and contractual protections particularly important.
Several questions therefore become relevant.
What Happens If the Audit Is Delayed?
SolidProof estimates approximately 6.5 weeks for the audit, with the broader process expected to take around 10 weeks, including remediation and the final report.
The community can therefore examine what protections exist if the work takes substantially longer than expected.
What Happens If a Deliverable Is Incomplete?
The proposal includes several expected deliverables, including audit findings, reports, recommendations and verification of fixes.
The exact acceptance criteria for those deliverables are important when evaluating an upfront payment arrangement.
What Happens If the Scope Changes?
The $70,800 SolidProof price is fixed for the agreed scope.
However, the proposal states that changes to scope, additional review rounds or fixes that are materially larger than the reported findings are outside the quoted arrangement.
This makes the definition of the original audit scope an important part of the governance discussion.
What Happens If LUNC Moves During the Voting Period?
The proposed 20% buffer is intended to address LUNC price volatility and transfer costs during the seven day governance voting period.
The proposal says unused buffer funds would be returned to the community pool.
The payment mechanism therefore involves not only the USD value of the audit but also the amount of LUNC required when the payment is executed.
Terra Classic Has Another Audit Proposal to Compare
The discussion has expanded because a separate proposal for an Oak Security audit of the Terra Classic core chain has also been presented.
According to the published comparison, the Oak proposal lists a $72,000 fixed audit fee, compared with SolidProof’s $70,800 fee.
The proposed structures are different.
The Oak proposal requests $74,000 for the audit and a buffer, while the SolidProof proposal requests $84,960 for the audit payment and buffer. The SolidProof proposal also includes a separate $20,000 allocation for OrbitLabs remediation, whereas the Oak proposal describes remediation through other contributors without an additional remediation fee in the same structure.
This gives LUNC holders another proposal to examine when considering:
- Audit scope
- Auditor
- Payment structure
- Remediation responsibility
- Total community pool expenditure
- Post audit verification
- Upgrade implementation
The comparison is therefore not simply about which audit costs less.
The terms and responsibilities attached to each proposal are also relevant.
How Does This Relate to Pay Per Job Governance?
The payment debate also connects with a broader discussion that has appeared in Terra Classic governance over the years: whether community funded development should be tied more closely to completed work and defined deliverables.
Previous Terra Classic governance discussions have proposed payment models based on delivery, proof of work and specific development tasks rather than simply funding work without clearly defined completion conditions.
That does not automatically mean every security audit can use the same payment model.
Security firms may have their own commercial requirements, and audit work can involve significant resources before a final report is delivered.
However, the SolidProof proposal gives the community a concrete example to examine because the audit fee is paid upfront while the separate OrbitLabs remediation payment is linked to completion.
The key governance question is therefore whether the proposed payment structure provides sufficient protection for community funds while still allowing the audit to proceed under commercially workable terms.
What Should LUNC Holders Examine Before Voting?
The proposal puts several separate questions in front of the community.
First, there is the technical question:
Does Terra Classic need a comprehensive independent security audit of its current codebase?
Second, there is the financial question:
Is the proposed $70,800 audit fee appropriate for the defined scope?
Third, there is the payment question:
Should the audit fee be paid entirely upfront?
Fourth, there is the treasury protection question:
What contractual protections exist if the work is delayed, incomplete or materially different from the agreed scope?
And finally, there is the alternative proposal question:
How does the SolidProof structure compare with other available audit proposals?
These questions can be considered independently rather than treating the audit itself and the payment structure as the same issue.
The Bigger Issue for Terra Classic Governance
Proposal #12228 is ultimately about more than one audit.
It highlights how Terra Classic uses its community pool to fund critical technical work.
An independent security audit could provide information about vulnerabilities in the current blockchain. At the same time, the way the community pays for that work determines how treasury risk is distributed between the community and the service provider.
The SolidProof proposal therefore presents two separate issues:
Security: How thoroughly should Terra Classic review its current codebase?
Treasury: How should the community protect its funds while paying for that work?
Those questions are important because the technical value of an audit and the financial structure of its contract are not the same thing.
The Question for the LUNC Community
Terra Classic Proposal #12228 proposes a $70,800 upfront payment to SolidProof, plus a 20% buffer for price volatility and transfer costs. It separately proposes $20,000 for OrbitLabs remediation work, with that payment scheduled after completion.
The proposal therefore gives LUNC holders a clear governance issue to examine:
Should the community fund the SolidProof audit through an upfront payment, or should the payment be structured around milestones and completed deliverables?
The answer depends on the terms of the agreement, the defined scope, the protections available to the community and the payment requirements of the auditor.
For LUNC holders, the key issue is not simply whether Terra Classic should be audited.
It is also how community funds should be protected while the audit is being carried out.
What do you think about the $70,800 upfront payment structure?
