The decentralized music streaming protocol Audius has become the latest DeFi platform to lose money to hackers.
Audius, a decentralized music streaming protocol, reported on Sunday, July 24, that hackers stole money from the community’s finances.
According to Audius, hackers used malicious governance votes to steal money from the protocol. The Audius team said:
“Hello everyone. Our team is aware of reports of fraudulent transfers of AUDIO tokens from community finance. We are actively investigating and will report as soon as details are available. If you would like to assist the response team, please contact us. “
Security company CertiK said hackers have successfully modified certain configurations of smart contracts used in streaming systems for music streaming protocols.
By making these changes, hackers were able to control smart contracts.
(1/2) The attacker calls the “Initialize” function of the Audius Governance Agreement to change the configuration (through reinitialization) such as “Voting Period”, “Delayed Execution”, and “Parental Address”. did.
The attacker then sent a malicious proposal (ID 85).
CertiK alert (@CertiKAlert) July 24, 2022
The attacker then created and approved a governance proposal (Proposal # 85). The proposal was aimed at transferring 18 million AUDIO tokens from community finance.
On-chain data revealed that the attack occurred on Saturday at 7 pm ET. The 18 million AUDIO tokens were worth about $ 6 million, but due to the high slippage of the market, the attackers could only sell 705 ethers ($ 1.1 million).
The stolen funds are now at the hacker’s address. The Audius team added that they identified and fixed a problem with smart contracts. It told the community that post-mortem reports would be provided shortly.
While waiting for the report, the Audius team said it had suspended smart contracts. Audius is one of the leading distributed music streaming protocols. This protocol allows artists to monetize their work using governance and utility tokens called AUDIO. AUDIO tokens are currently available on Ethereum and Solana networks.