Audius Hack
What happened
On July 23, 2022, Audius's Ethereum governance, staking, and delegation contracts were compromised through a proxy storage collision that enabled repeated initialization. The attacker used the resulting governance takeover to transfer 18,564,497 AUDIO from the community treasury.
A custom proxy and the implementation's Initializable state used the same storage slot. The collision made the initialization guard ineffective and allowed repeated calls to initialize().
Case & protocol details
Attack Timeline
Audius's custom upgradeability proxy stored its proxy-admin address in storage slot 0, where OpenZeppelin's Initializable implementation also expected its initialized and initializing flags. Bytes in that address made both flags evaluate as true, so the initializer modifier could be called repeatedly. The attacker reinitialized the Governance, Staking, and DelegateManagerV2 contracts, created erroneous delegations, passed governance proposal #85, and moved 18,564,497 AUDIO from the community treasury.
Audius identified the issue and deployed mitigation and contract patches the same day.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-mortem rekt.news
- report Audius Governance Takeover Post-Mortem blog.audius.co
- transaction Transaction etherscan.io
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Blog reference blog.audius.co
- analysis Website reference cointelegraph.com
- analysis Website reference cryptonews.com
- analysis News reference news.coincu.com
- analysis OpenZeppelin: The Audius Governance Takeover blog.openzeppelin.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.