Cryptocurrency [loss] $1M+

"Audius Governance Takeover Post-Mortem 7/23/22"

2022-07-23 [vendor] Audius governance attack [chain] ethereum
Primary Source ↗
Financial Loss $1.1M (1,101,343 USD)
Blockchain(s) Ethereum

Incident Details

An attacker was able to create and pass a governance proposal to transfer out 18.5 million AUDIO tokens from the community treasury. They then successfully swapped these for 705 ETH (~$1.1 million).Audius halted the token and smart contracts while they patched the bug, and brought the network back online shortly afterward. The attacker had found and exploited a vulnerability in the way the contracts were written which allowed them to rewrite the governance voting rules and delegate 10 trillion AUDIO tokens to themselves for voting purposes. They then used those tokens to pass the malicious proposal. The contracts had been audited by OpenZeppelin and Kudelski, but neither group caught the vulnerability. Audius stated that a plan for dealing with the loss of community funds was still under discussion.

Total loss estimated at $1,101,343.

Technical Details

Initial Attack Vector
Governance attack / malicious on-chain proposal
Vendor / Product
Audius governance attack

Timeline

  1. 2022-07-23 Breach occurred
  2. 2022-07-23 Publicly disclosed