Decentralized Music Platform Audius Identifies Source of USD 6M Exploit, Says it Applied a Patch
2022-07-26 15:22:03 Primitive Reading

 

Source: AdobeStock / MR

 

Decentralized music platform Audius has identified the bug that had allowed a hacker to pass a malicious governance proposal and transfer tokens worth USD 6m, adding that they have applied a patch to regain control of the protocol.

In a post-mortem, the protocol said that a vulnerability in its governance, staking, and delegation contracts on Ethereum (ETH) allowed a hacker to exploit the contract initialization code on July 23 and maliciously transfer AUDIO 18m (USD 6.075m) held by the community treasury.

Audius said that the compromised set of contracts was audited by blockchain security firm OpenZeppelin on August 25, 2020, prior to deployment, and by another security firm Kudelski on October 27, 2021.

"Fortunately, the Audius team was able to develop and apply a patch to quickly regain control of the protocol before the attacker could do more damage," the team claimed.

At the time of the attack, the tokens were worth USD 6.1m. However, Etherescan transactions show that the attacker managed to run away with ETH 704.9 (worth USD 1.073m) after dumping the tokens that resulted in maximum slippage.

The team also claimed that the "vast majority" of Audius foundation, team, community, and other funds are safe and were unaffected by the incident. "Work is in progress in collaboration with the community on possible remediations for the loss of funds, and we are fortunate that many options are still available," they said.

Meanwhile, at 7:28 UTC on Monday morning, Audius' native token AUDIO is trading at around USD 0.33, down by 2% in a day and more than 4% in a week.

Notably, Audius is not the only decentralized finance (DeFi) project that has fallen victim to a hack over the past couple of days.

Virtual pet-owning game Neopets also confirmed late last week that it had suffered a breach of data, that email accounts and passwords "may have been affected," and they recommend that users change their passwords.

"Neopets recently became aware that customer data may have been stolen. We immediately launched an investigation assisted by a leading forensics firm. We are also engaging law enforcement and enhancing the protections for our systems and our user data," the company wrote in a Twitter thread on Thursday.

Disclaimer: This specification is preliminary and is subject to change at any time without notice. Amazon Finance assumes no responsibility for any errors contained herein.

Recommended reading
Star Cluster Launches Intuitive, Comprehensive Platform for Contracts in the Blockchain Industry

10-22     Amazon Finance     10814 Reading

2022 Blockbuster Work | Diversified Application Aggregation Metaverse Platform - King World is about to go online!

10-22     Amazon Finance     8779 Reading

GIIIO leads the new wave of metaverse development to build a decentralized metaverse ecological platform

10-22     Amazon Finance     7204 Reading

The global hot DAO ecological platform M-ZONE: DAO community round pre-sale has been fully opened

10-22     Amazon Finance     8258 Reading

VSTMEX:The Global Inclusive Digital Asset Trading Platform, Participates in the 2022 London Contract Trading Exhibition!

10-22     Amazon Finance     6843 Reading

Microsoft released DID, a decentralized identity system based on blockchain, marking the arrival of the future of decentralized digital identity

10-22     Amazon Finance     7091 Reading

NFT Lab and R3 Blockchain Alliance reached a strategic cooperation Jointly promote the development and construction of the NFTT platform

10-22     Amazon Finance     17379 Reading

Ecology Blockchain: Boost Traditional Enterprises in Accessing to the Decentralized Business Ecology

10-22     Amazon Finance     11599 Reading

A new generation of fully decentralized exchanges, Node Swap, is coming online

10-22     Amazon Finance     9234 Reading

FTN-DEX decentralized trading platform enters into a strategic partnership with Canadian foundation Oasis

10-22     Amazon Finance     9827 Reading

Is GameStop Developing an Ethereum-Based NFT Platform?

10-22     Martin Young     17087 Reading

Sberbank Expects to Register its Blockchain Platform in The Next Two Weeks

10-22     Dimitar Dzhondzhorov     15986 Reading

Standard Chartered Launches Blockchain-based Trade Finance Platform

10-22     Dimitar Dzhondzhorov     10512 Reading

Ukraine Shuts Down Illegal Cryptocurrency Platforms

10-22     Dimitar Dzhondzhorov     15112 Reading

Borderless Finance Platform Gluwa Taps Infura Transactions (ITX) To Reduce Ethereum Transa

10-22     Amazon Finance     16411 Reading