+1 (970) 414-2609
  • About Us
  • Directory
  • Contact Us
  • Global News
Tuesday, August 9, 2022
  • Home
  • Academy
  • Active Campaign
  • Youth Programs
  • Join the Club
No Result
View All Result
Boys & Girls Clubs of Senegal
No Result
View All Result
Home Africa News

Audius: Autopsy of $6m music heist reveals some out of key notes

by shubham pandey
July 25, 2022
in Africa News
Reading Time: 3 mins read
A A
464
SHARES
1.8k
VIEWS
Share on FacebookShare on Twitter

Hacks within the cryptocurrency domain are very frequent. Recently, a decentralized music platform Auduis suffered as it lost 18.5 million AUDIO tokens ($6m) following a malicious attack.

Broken strings
On 24 July, the Audius community treasury lost a significant amount due to an exploit in the contract initialization code that allowed repeated invocations of the “initialize” function. The respective team shared this development on the social media platform.

Hello everyone – our team is aware of reports of an unauthorized transfer of AUDIO tokens from the community treasury. We are actively investigating and will report back as soon as we know more.

If you’d like to help our response team, please reach out.

— Audius 🎧 (@AudiusProject) July 24, 2022

Different agencies/firms took efforts to release their post-mortem report for a deep analysis behind the said attack.

A crypto and blockchain security analytic platform named Certik released a simple overview to highlight the same.

#CommunityAlert 🚨

The @AudiusProject has been exploited for a total of ~$6M worth of AUDIO tokens, the tokens were sold for 705 ETH.

The attacker modified the Audius governance contract’s configurations, then proposed and executed a malicious proposal draining 18.5M AUDIO. pic.twitter.com/djuAO1Jarv

— CertiK Alert (@CertiKAlert) July 24, 2022

Here, the attacker modified the Audius governance contract’s configurations, then proposed and executed a malicious proposal draining 18.5m AUDIO.

This allowed an attacker to modify the voting system and set erroneous stake values in the network.

Ergo, leading to a malicious transfer of 18m AUDIO tokens held by the Audius governance contract (referred to as the “community treasury”) in their wallet. 

Later, the attackers were able to do a proposal, pass it, send themselves all the treasury tokens, then dump it on Uniswap in one transaction. Notably, the attacker sold 18m AUDIO tokens for 705 ETH ($1.1m).

It seems like $6M in $Audio were only traded for just a little over $1M in ETH. https://t.co/eAQDvBoTJ6 pic.twitter.com/gRf4yw3Qdv

— MistTrack🕵️ (@MistTrack_io) July 24, 2022

In addition, another firm, Go+ Security too shared a brief analysis on 24 July to highlight the said attack. In a blog, the firm added a small flowchart asserting the full attack vector.

ADVERTISEMENT

Tamper with vote parameters -> submit malicious proposal -> Tamper with vote weight -> Vote -> Execute proposal

The firm further added an in-depth analysis including screenshots of the aforementioned timing of the unfortunate event. Another blockchain investigator Peckshield narrowed down the fault to Audius’ storage layout inconsistencies.

The issue of @AudiusProject lies in inconsistent storage layout between its proxy and impl. In particular, the collision of Audius Community Treasury contract results in an equivalence of disabling the initializer modifier. The proxyAdmin addr (0x..abac) plays a role here. pic.twitter.com/x4CqRncahp

— PeckShield Inc. (@peckshield) July 24, 2022

Damage control?
The Audius team updated that the vulnerabilities were patched, but many features such as token transfer and balance display have not been activated because of concerns about risks.

“This was achieved by “proxy-upgrading each contract to a minimal BlockingContract that did not contain the same bug. This prevented further repeated invocations after relegating proxyAdmin control to a predefined address owned by the team.”

But did it help the affected token? Well not really. The token witnessed a massive fall on CoinMarketCap as evident in the graph below.

Source: CoinMarketCap

At the time of writing, the token (AUDIO) suffered a fresh 2% correction as it slid past the $0.33 mark.

news image

Previous Post

Lawmakers Pressure Biden Administration on Monkeypox Failure

Next Post

Biden to huddle virtually with labor leaders, CEOs on semiconductor bill

Related Posts

Republicans lash out at Justice Department after FBI searches Trump’s Mar-a-Lago home

by camellia wrona
August 9, 2022

Republican lawmakers and officials accused the Biden administration on Monday night of weaponizing the Justice Department for political ends after...

Read more

Minnesota primary expected to set Walz, Jensen matchup

by by steve karnowski - associated press
August 9, 2022

MINNEAPOLIS (AP) — Democratic Gov. Tim Walz and Republican challenger Scott Jensen, already jousting for months in Minnesota’s marquee race...

Read more

Malibongwe festival returns with a tribute to women

by mandisa ndlovu
August 9, 2022

Woman artists across the country are taking up space and making their mark in the music industry by raising awareness...

Read more

Can Your iPad Get A Virus From Safari? Here’s What We Know

by yuri fleishman
August 9, 2022

Framesira/Shutterstock Safari is one browser on your iPad which allows you to access a sprawling amount of information across the...

Read more

Ex-DepEd chief Briones speaks up on controversial P2.4-B laptop purchase 

by merlina hernando-malipot
August 9, 2022

Ex-DepEd chief Briones speaks up on controversial P2.4-B laptop purchase  Former Education Secretary Leonor Briones has spoken up on the...

Read more

Roads, streets named after colonialists must be reversed – Obono-Obla

by damiano gerli
August 9, 2022

Former presidential aide, Chief Okoi Obono-Obla has canvassed the re-christening of roads, streets and boulevards in State capitals and the...

Read more
Next Post

Biden to huddle virtually with labor leaders, CEOs on semiconductor bill

ADVERTISEMENT

Trending Posts

World News

Volodymyr Zelenskyy Wants West To Restrict All Russian Travelers

by joan grumbles
August 9, 2022

Ukrainian President Volodymyr Zelenskyy on Monday pleaded with Western leaders to further isolate the Kremlin by closing their borders to...

Read more

Volodymyr Zelenskyy Wants West To Restrict All Russian Travelers

Fears Of Nuclear Incident Grow As Shells Strike Plant That Dwarfs Chernobyl

China to create doomsday nuclear ‘super torpedo’ to mimic Russia’s tsunami Poseidon

Russia launches Iranian satellite amid Ukraine war concerns

‘I have to follow the rules’

Live: Ukraine reports heavy Russian shelling along Donbas front

Load More

Popular Posts

LGBTQ+ Rights In Senegal

by BGC Senegal
November 26, 2019

We work diligently to prevent suicide through youth empowerment, counseling and support programs.

COVID-19 In Senegal

by BGC Senegal
March 23, 2020

An online learning platform to support Senegal in these moments of self-confinement and social distancing...

I am a “Talibé” In Senegal

by BGC Senegal
February 28, 2020

According to Human Rights Watch, more than 100,000 children in Senegal are forced to beg on the streets for food...

Facebook Twitter LinkedIn Youtube

NEWSLETTER

Subscribe to our newsletter and be the first to know about our upcoming events and programs.

QUICK LINKS

  • About Us
  • Learning Center
  • Active Campaign
  • Privacy Policy
  • Terms and Conditions
  • Contact us
  • Global News

CONTACT INFO

  • [email protected]
  • For donations contact us at: [email protected]

© 2019-2022 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

No Result
View All Result
  • Home
  • Academy
  • Active Campaign
  • Youth Programs
  • Join the Club

© 2019-2022 Boys & Girls Clubs of Senegal. We are a 501 (C)(3) organization and donations are tax deductible. - EIN: 83-3699796

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT

Add New Playlist