Audius Community Treasury Hacked for ~18.5M AUDIO Tokens. $6M Worth of Stolen Tokens Dumped for Just $1.1M, Due to High Slippage on Uniswap

|
About Audius Project:Audius is a decentralised music streaming service, built on POA Network, an Ethereum sidechain, and later moved some services to the Solana blockchain. It lets artists upload their tunes to the app and connects fans directly with artists and exclusive new music. Hack Recap:The attacker called the "initialize" function in the Audius governance contract to modify configurations (through re-initialization) such as "voting period", "execution delay", and "guardian address". The attacker created and passed a malicious governance proposal to transfer out 18.5M AUDIO tokens from the community treasury. Then, they successfully swapped these $6M worth of tokens on Uniswap for only $705 ETH (~$1.1 Million), due to high slippage. Audius Team Response:
The Stolen funds are currently at this address: 0xa0c7BD318D69424603CBf91e9969870F21B8ab4c submitted by /u/SurenRongyao |