According to Beosin Alert monitoring and warning, the Terra chain was suspended due to an emergency upgrade. It seems that someone exploited the IBC vulnerability to mint multiple tokens on the Terra chain, including ASTRO. The Beosin security team analyzed and found that after the attacker instantiated the contract on Terra, he took advantage of the reentrancy vulnerability of the timeout callback in ibc-hooks and transferred about 60 million ASTRO, 3.5 million USDC, 500,000 USDT and 2.7 BTC.
This vulnerability was disclosed in April this year and is a vulnerability in the cosmos basic library, but Terra has not fixed it.