Decentralized Music Platform Audius Releases Post-Mortem from Attack
Decentralized music platform Audius released the post-mortem from the attack. Audited contracts were compromised due to an exploit in the contract initialization code that allowed repeated invocations of the "initialize" function. This allowed an attacker to modify the voting system and set erroneous stake values in the network, leading to a malicious transfer of 18MM $AUDIO tokens held by the Audius governance contract (referred to as the "community treasury") their wallet.
In addition, Audius claims that all remaining funds are safe and fixes have been deployed. At this point all remaining smart contract components have been updated and unpaused except staking and delegation. The team expects to have these online within the next couple of days, after changes have been reviewed.