Community Pool Spend: Oak Security Audit of the Terra Classic Core Chain

Status: Discussion. Not yet submitted on-chain.

Full proposal document (PDF, 8 pages): Oak Security Audit Proposal – Terra Classic Core Chain
Proposer: Luna Classic DAO (lead), in partnership with Bumeo Capital
Named partners: Renzo (Luna Classic DAO) and Till, also known as Frag (Bumeo Capital)
Type: Community Pool Spend
Amount: US$74,000 in LUNC from the community pool: US$72,000 for Oak Security’s audit fee plus a US$2,000 buffer for the Terra Classic on-chain tax and the exchange costs of converting the LUNC to USD. The LUNC goes to a DAO multisig, which exchanges it for USD and pays Oak Security in USD (the LUNC amount will be fixed from a price reference at submission; see Budget)


Summary

This proposal funds one independent security audit of the Terra Classic core chain by Oak Security, exactly as Oak Security proposed it in its quote “Proposal - Terra Classic Core Security Audit” (v1.0, 4 September 2026).

  • Scope (Oak’s wording): “Security audit of the x/treasury, x/vesting, x/dyncomm, x/market, x/oracle, x/tax, and x/taxexemption modules, the app package, and the wasmbinding package in the classic-terra/core repository.” The quote is based on commit 9a5ee563874ce3906c3ca7069f0160de51f89c40.
  • Tier: Seed Security Audit
  • Price: US$72,000 fixed, as quoted, paid to Oak Security in USD
  • Duration: 3 weeks, as quoted
  • Remediation review: included at no additional cost for three weeks after the Initial Audit Report
  • Development cost: $0

Luna Classic DAO and Bumeo Capital commit to fixing all findings from Oak Security’s audit free of charge, through Renzo (Luna Classic DAO) and Till, also known as Frag (Bumeo Capital), working jointly. The community pays only Oak Security’s audit fee, plus the on-chain tax and exchange costs of converting it.

Oak Security also offered a Signature Security Audit at US$117,000. This proposal does not choose it.

Rationale

The modules in scope carry Terra Classic’s monetary and fee logic: treasury, tax and tax exemption, oracle, market, dynamic commission and vesting. The scope also covers the app package that wires the chain together and the wasmbinding package that connects smart contracts to chain functions. An independent audit of this code gives validators, developers and holders a public, expert review of the chain’s core.

The partnership keeps the cost to the community pool to the audit fee alone, plus the on-chain tax and exchange costs of converting it. Oak Security finds and reports the issues. Renzo and Till (Frag) fix them at no charge, and Oak Security reviews those fixes at no additional cost during its three-week remediation window.

Oak Security specializes in Cosmos SDK chain code and CosmWasm, the same stack Terra Classic runs. That is why this proposal names them: the work is a core-chain module audit, and Oak has already audited Cosmos SDK modules, Interchain Security, CosmWasm bindings and custom app-chain logic for multiple live networks. Details and public sources are in “About Oak Security” below.

Scope of work, as quoted by Oak Security

Security audit of the x/treasury, x/vesting, x/dyncomm, x/market, x/oracle, x/tax and x/taxexemption modules, the app package and the wasmbinding package in the classic-terra/core repository.

The quote is based on commit 9a5ee563874ce3906c3ca7069f0160de51f89c40. In Oak Security’s words, “Any commit hashes stated in this proposal serve as a reference to the initial scope and are expected to change before the audit starts.” The final audit commit will be agreed with Oak Security and published before work starts.

What Oak Security’s audit includes

As listed in Oak Security’s proposal:

  • Blinded process: multiple security auditors independently review every line of code in parallel and share their findings only towards the end of the audit.
  • Coverage: every line of code in scope is covered by at least 2 senior security researchers (Seed Security Audit).
  • Approach: initial static code analysis and manual code review, with most of the time spent on manual review. Each auditor may add methods such as edge-case tests, economic modeling where appropriate, and fuzz testing.
  • Direct communication: a group channel with the audit team (Telegram, Slack, Discord, Element or email).
  • Initial Audit Report: a detailed report of all findings, each with a severity rating and recommended remediation.
  • Remediation Review: the auditors review any remediations at no additional cost for three weeks after delivering the Initial Audit Report.
  • Final Audit Report: categorizes all findings as resolved or acknowledged, with the option to include a statement on each issue’s status.
  • Publication: the Final Audit Report is published on GitHub.
  • Announcement: an optional X/Twitter announcement.

Price and duration, as quoted

Seed Security Audit (chosen) Signature Security Audit (not chosen)
Researchers At least 2 senior security researchers in parallel 4–5 senior security researchers in parallel
Weekly rate US$24,000 per week US$39,000 per week
Quoted price US$72,000 US$117,000
Duration 3 weeks 3 weeks
Start date To be discussed To be discussed

Oak Security’s quote adds: “The price and duration are based on the outlined scope at the specified commit. Should the scope increase by more than 20%, a new quote/statement of work will be necessary.” This proposal does not change the quoted scope.

About Oak Security

Oak Security (oaksecurity.io) is an independent Web3 security firm that has worked since 2017. Its public figures, as stated on its website and GitHub report archive, are:

  • 600+ security engagements completed since 2017
  • 50+ senior security researchers, including specialists with advanced degrees in computer science, cryptography, economics, engineering and finance
  • 9+/10 average client rating
  • Published final reports on GitHub: github.com/oak-security/audit-reports

The firm lists Cosmos (CosmWasm), Cosmos SDK chain code, EVM, Solana, Polkadot/Substrate, Stellar (Soroban), virtual machines, consensus protocols and light clients, bridges, and DeFi as core specializations. That mix matches this engagement: Terra Classic core modules are Cosmos SDK Go code, wired through an app package, with a wasmbinding package that exposes chain functions to CosmWasm contracts.

Cosmos and Cosmos SDK experience

Public client statements on oaksecurity.io and published reports on GitHub include work that is directly comparable to a Terra Classic core-module audit:

  • Cosmos SDK core modules. Oak published an audit of Cosmos SDK v0.47 modules intended for Gaia / Cosmos Hub (v15), working with Informal Systems and Binary Builders. The report identified critical and major issues in core SDK code, the same class of software as the modules in this proposal’s scope.
  • Interchain Security and CosmWasm VM. Team bios and published work cover Interchain Security and the CosmWasm virtual machine. Oak has also written publicly on Cosmos SDK BeginBlock / EndBlock risk (unmetered functions), including issues first raised in its Interchain Security work.
  • Sei. Jayendra Jog, co-founder of Sei Labs: Oak audited Sei Chain, CosmWasm bindings, and modifications of both Cosmos SDK and Tendermint.
  • Neutron / Hadron Labs. Spaydh, co-founder and CEO of Hadron Labs: repeated engagements on both CosmWasm contracts and Cosmos SDK blockchain codebases.
  • Stride. Riley Edmunds, co-founder of Stride Labs: Oak reviewed Stride’s liquid staking design, custom SDK modules and CosmWasm contracts.
  • Stargaze. Shane Vitarana, co-founder: several CosmWasm audits; Oak described as one of the few teams that “understand CosmWasm in and out.”
  • Noble. Jack Zampolin (Strangelove): extensive work launching and upgrading Noble, a Cosmos app-chain for native assets.
  • Babylon / SatLayer. Jia Jian Goi, Product Lead, SatLayer: CosmWasm contracts for Babylon Genesis; cited Oak’s “deep technical insight into the Cosmos stack and CosmWasm.”
  • Other Cosmos and IBC work. Public report folders and coverage include Axelar, Archway, Evmos, Astroport, DAO DAO, AtomOne (a Cosmos Hub fork, including governance and IBC light-client changes), Nym (CosmWasm), and historical Terra-era CosmWasm work such as Anchor. The GitHub archive maintains dedicated Cosmos SDK, CosmWasm, Neutron, and Cosmos bridges / cross-chain sections.

Other major chains and L1 / VM work

The same firm audits Layer 1 protocol changes and virtual machines outside Cosmos. That matters here because this scope includes chain-level packages (app, wasmbinding), not only application contracts.

  • Stellar. Oak lists Stellar (Soroban) as a specialization and published a public audit of Stellar Core Protocol 24 Changes (November 2025) in its GitHub archive. Lead auditor bios also cite Stellar protocol work.
  • Filecoin. Published work on Filecoin’s Ethereum Virtual Machine implementation (FEVM).
  • Polkadot / Substrate. Including Snowbridge, the light-client bridge between Ethereum and Polkadot, plus Substrate / ink! coverage.
  • Solana, EVM / Solidity, Move, and other stacks. Listed specializations and report folders cover Solana programs, EVM contracts and L2s, and Move contracts (Aptos / Sui), so the firm is not a single-ecosystem shop.

Why this record is relevant to Terra Classic: the in-scope code is Cosmos SDK module and app-wiring code plus CosmWasm bindings. Oak has audited that exact combination (SDK modules, custom app-chain logic, Tendermint / CometBFT-adjacent changes, and wasmbinding-style interfaces) on live Cosmos networks, and has also audited L1 protocol changes on Stellar and VM implementations on Filecoin. Public reports and client names are on oaksecurity.io and github.com/oak-security/audit-reports, so validators can check them independently.

Entry criteria (before work starts)

  • This proposal passes.
  • Oak Security’s written confirmation of the engagement, including payment in USD, is signed.
  • The audit commit is agreed with Oak Security and published.
  • Renzo (Luna Classic DAO) and Till (Frag, Bumeo Capital) confirm they are available to fix findings at no cost to this proposal.

Exit criteria (completion)

  • Oak Security delivers the Initial Audit Report.
  • Renzo and Till (Frag) fix the findings jointly, at no cost, and Oak Security reviews the fixes within its three-week remediation window.
  • Oak Security publishes the Final Audit Report on GitHub, with each finding categorized as resolved or acknowledged.
  • The report and fix status are posted in this Agora thread.

Budget

Item Amount
Oak Security Seed Security Audit of the quoted scope, including the Initial Audit Report, three weeks of remediation review and the Final Audit Report US$72,000
Buffer for the Terra Classic on-chain tax (1.5%) on the multisig’s transfer of LUNC to the exchange, and the exchange trading fee and slippage on conversion to USD; unused buffer returned to the community pool US$2,000
Fixing all audit findings (Renzo and Till (Frag), for Luna Classic DAO and Bumeo Capital) $0
Development $0
Total requested US$74,000, paid from the community pool in LUNC (US$72,000 audit fee plus US$2,000 buffer for on-chain tax and conversion costs)

The community pool pays LUNC to a DAO multisig. The multisig exchanges the LUNC for USD and pays Oak Security in USD. Planned details:

  • Message: one MsgCommunityPoolSpend from the governance module account to the DAO multisig, in uluna.
  • LUNC amount: US$74,000 worth of LUNC, set from a LUNC price reference taken shortly before on-chain submission. The price source, date and resulting LUNC / uluna amount will be posted here before submission.
  • Recipient: a DAO multisig. The multisig address and signers will be posted here before submission.
  • Conversion and payment: the multisig sends the LUNC to an exchange, sells it for USD (USDT, USDC or fiat; to be confirmed) and pays Oak Security US$72,000 in USD.
  • Tax and conversion buffer: the community pool payout to the multisig is not taxed. The multisig’s transfer of LUNC to the exchange is taxed at the current on-chain rate of 1.5%, and converting to USD costs an exchange trading fee (about 0.1%) and slippage (estimated at about 0.75%). US$72,000 ÷ (0.985 × 0.999 × 0.9925) = US$73,723, rounded up to US$74,000.
  • Unused buffer: any LUNC or USD left in the multisig after Oak Security is paid US$72,000 is returned to the community pool, and the transaction is posted here.
  • Deposit: per the governance parameters at the time of submission.

Timeline

Oak Security’s quote lists the start date as “to be discussed.” All steps below count from the day this proposal passes.

When Milestone
After passage Agreement signed with Oak Security, audit commit agreed, start date set
Weeks 1–3 of the audit Audit fieldwork (3 weeks, as quoted)
End of week 3 Initial Audit Report delivered
Following 3 weeks Renzo and Till (Frag) fix findings; Oak Security reviews the fixes at no additional cost
Completion Final Audit Report published on GitHub; summary and fix status posted on Agora

What this proposal does not do

  • It does not fund any development.
  • It does not change any chain parameters.
  • It does not approve any chain software upgrade. Any upgrade that includes audit fixes would follow its own process.

How this compares with Proposal 12228

Proposal 12228 (“Fund Terra Classic Security Audit by SolidProof & Fixes by OrbitLabs”) is in its on-chain voting period until 1 October 2026. We are posting this proposal so the community can compare both options side by side. The main differences, based on the 12228 discussion thread:

Proposal 12228 This proposal
Auditor SolidProof Oak Security
Audit fee US$70,800 fixed US$72,000 fixed
Amount requested for the audit US$84,960 (fee plus a 20% buffer, unused buffer returned) US$74,000 (fee plus a US$2,000 buffer for on-chain tax and conversion costs, unused buffer returned)
Fixing findings OrbitLabs, US$20,000, paid after completion Renzo and Till (Frag), US$0
Total cost to the community pool US$90,800 US$72,000, plus the on-chain tax and conversion costs actually paid (up to US$2,000)
Scope Custom modules, Cosmos SDK module overrides, fee handling, app and IBC wiring, CosmWasm integration, SDK 0.53 upgrade handlers and store migration, adversarial simulation x/treasury, x/vesting, x/dyncomm, x/market, x/oracle, x/tax, x/taxexemption, the app package and the wasmbinding package
Chain upgrade for fixes Prepared by OrbitLabs as part of their work Follows its own process

Team

  • Luna Classic DAO leads the proposal, in partnership with Bumeo Capital.
  • Named partners: Renzo (Luna Classic DAO) and Till, also known as Frag (Bumeo Capital).
  • Audit fixes at no cost: Renzo and Till (Frag), working jointly, for Luna Classic DAO and Bumeo Capital.

Experience: Renzo and Till have both worked on-chain since the Terra crash, on Layer 1 and on Layer 2. Till, also known as Frag, has been part of the core group working on the chain’s security for up to four years, alongside the other contributors who have also worked on it.

Voting options

  • YES: approve a community pool spend of US$74,000 in LUNC to a DAO multisig, which exchanges it for USD and pays Oak Security US$72,000 in USD for its Seed Security Audit of the Terra Classic core chain as described above, with any unused buffer returned to the community pool and findings fixed by Renzo and Till (Frag) at no cost.
  • NO: do not approve this spend.
  • NO WITH VETO: you consider this proposal spam or an abuse of governance. If the veto threshold is reached, the deposit is burned.
  • ABSTAIN: you do not wish to vote for or against, but want your vote counted toward quorum.

To be finalized before on-chain submission

These items will be posted in this thread before the proposal goes on-chain:

  1. Oak Security’s written confirmation of the engagement, including payment in USD and the payment method (USDT, USDC or fiat).
  2. The final audit commit, agreed with Oak Security.
  3. Payment details: the LUNC price reference and date, the resulting LUNC and uluna amount, the DAO multisig address and its signers, the exchange used to convert the LUNC, and how the multisig pays Oak Security in USD.
  4. The deposit amount for the on-chain submission.
  5. A link to Oak Security’s proposal document.

Questions for the community

We’d like feedback on the following before moving to an on-chain vote:

  1. Is the scope (treasury, vesting, dyncomm, market, oracle, tax, taxexemption, app and wasmbinding) the right set of code to audit first?
  2. Is the Seed Security Audit the right tier, or should the community consider the Signature Security Audit (US$117,000)?
  3. Decided: payment goes through a DAO multisig, which exchanges the LUNC for USD and pays Oak Security in USD (see Budget). Feedback on the multisig signers is welcome once they are posted.
  4. How do you see this proposal alongside Proposal 12228?
  5. Any other concerns or questions for Luna Classic DAO, Bumeo Capital or Oak Security.

References


Proposal document

The full PDF is here: Oak Security Audit Proposal – Terra Classic Core Chain. Key pages:




This is a discussion draft. Items listed under “To be finalized before on-chain submission” will be resolved and posted here before the proposal goes on-chain. Claims in “About Oak Security” are taken from Oak Security’s public website and published GitHub reports so validators can check them independently.

Jfyi. The mentioned git commit hash does not include MM2.0

1 Like

Thanks @StrathCole, good catch. You’re right, the commit in Oak’s quote (9a5ee563) predates MM2.0.

That’s intentional. This proposal covers the core modules exactly as Oak quoted them. MM2.0 and USTC staking will get their own separate, targeted audit with Oak Security. We’re arranging that on a per-credit basis, so the community doesn’t pay for a second full audit of the whole core chain just to cover the new code.

We’ll post the scope, the commit and the cost of that second engagement here once they’re confirmed with Oak. The final audit commit for this proposal will also be agreed with Oak and posted in this thread before on-chain submission.