2020 - 2021 Best Cryptocurrency News Investment Guide

Decentralized Music Platform Audius Identifies Source of USD 6M Exploit, Says it Applied a Patch
2022-07-26 15:21:47 Primitive Reading


Source: AdobeStock / MR


Decentralized music platform Audius has identified the bug that had allowed a hacker to pass a malicious governance proposal and transfer tokens worth USD 6m, adding that they have applied a patch to regain control of the protocol.

In a post-mortem, the protocol said that a vulnerability in its governance, staking, and delegation contracts on Ethereum (ETH) allowed a hacker to exploit the contract initialization code on July 23 and maliciously transfer AUDIO 18m (USD 6.075m) held by the community treasury.

Audius said that the compromised set of contracts was audited by blockchain security firm OpenZeppelin on August 25, 2020, prior to deployment, and by another security firm Kudelski on October 27, 2021.

"Fortunately, the Audius team was able to develop and apply a patch to quickly regain control of the protocol before the attacker could do more damage," the team claimed.

At the time of the attack, the tokens were worth USD 6.1m. However, Etherescan transactions show that the attacker managed to run away with ETH 704.9 (worth USD 1.073m) after dumping the tokens that resulted in maximum slippage.

The team also claimed that the "vast majority" of Audius foundation, team, community, and other funds are safe and were unaffected by the incident. "Work is in progress in collaboration with the community on possible remediations for the loss of funds, and we are fortunate that many options are still available," they said.

Meanwhile, at 7:28 UTC on Monday morning, Audius' native token AUDIO is trading at around USD 0.33, down by 2% in a day and more than 4% in a week.

Notably, Audius is not the only decentralized finance (DeFi) project that has fallen victim to a hack over the past couple of days.

Virtual pet-owning game Neopets also confirmed late last week that it had suffered a breach of data, that email accounts and passwords "may have been affected," and they recommend that users change their passwords.

"Neopets recently became aware that customer data may have been stolen. We immediately launched an investigation assisted by a leading forensics firm. We are also engaging law enforcement and enhancing the protections for our systems and our user data," the company wrote in a Twitter thread on Thursday.

Disclaimer: This specification is preliminary and is subject to change at any time without notice. MYTOKEN assumes no responsibility for any errors contained herein.

Recommended reading
MyScore is a decentralized pan-entertainment platform, rewriting the quiz industry landscape

10-22     Amazon Finance     11293 Reading

The Web3 technology revolution launched by tech geeks around the world DAS next generation public foundation chain and distributed trust collaboration platform

10-22     Amazon Finance     11754 Reading

Web3.0 aggregation platform Metaspace Protocol may have a subversive effect on the times

10-22     Amazon Finance     9950 Reading

Star Cluster Launches Intuitive, Comprehensive Platform for Contracts in the Blockchain Industry

10-22     Amazon Finance     11199 Reading

The world's first pan-entertainment social metaverse platform, ARES is about to shine

10-22     Amazon Finance     8119 Reading

The world's first DAO-based ecological matching and trading platform, Space DAO, will be launched on major application platforms soon

10-22     Amazon Finance     10829 Reading

Dimension Labs and LeibnizAILab reached a cooperation to build the Dimension AI end-cloud collaboration platform

10-22     Amazon Finance     6717 Reading

VSTMEX:The Global Inclusive Digital Asset Trading Platform, Participates in the 2022 London Contract Trading Exhibition!

10-22     Amazon Finance     8879 Reading

Decentralized Autonomous Game----"Chain Entertainment Legend"

10-22     Amazon Finance     10000 Reading

Decentralized Autonomous Game----"Chain Entertainment Legend"

10-22     Amazon Finance     9966 Reading

The First Ecological Aggregation Platform Appeared on the Chain Game Racing Tracks Metalab Obtained the Heavyweight Strategic Investment of CMT Digital

10-22     Amazon Finance     8653 Reading

Metasea officially launched, the world's first multi-chain aggregated NFT digital trading platform was born

10-22     Amazon Finance     11288 Reading

BLUS Game Association has officially changed its name to BluSea NFT trading platform and obtained investment from a number of international renowned institutions

10-22     Amazon Finance     6165 Reading

DataBase Labs has officially launched a project that it says will create the first NFT trading platform that aggregates across chains!

10-22     Amazon Finance     12415 Reading

NFT Lab and R3 Blockchain Alliance reached a strategic cooperation Jointly promote the development and construction of the NFTT platform

10-22     Amazon Finance     17392 Reading