Audius Hack

TOTAL LOST $6.0M
Medium Access Control Attacks ethereum

What happened

On July 23, 2022, Audius's Ethereum governance, staking, and delegation contracts were compromised through a proxy storage collision that enabled repeated initialization. The attacker used the resulting governance takeover to transfer 18,564,497 AUDIO from the community treasury.

Technical Root Cause

A custom proxy and the implementation's Initializable state used the same storage slot. The collision made the initialization guard ineffective and allowed repeated calls to initialize().

Case & protocol details

Classification Proxy Storage Collision / Governance Takeover
Protocol Type Exploit/Other
Affected asset / contract AUDIO
Smart Contract Language Solidity
Protocol Twitter/X @audius

Attack Timeline

Audius's custom upgradeability proxy stored its proxy-admin address in storage slot 0, where OpenZeppelin's Initializable implementation also expected its initialized and initializing flags. Bytes in that address made both flags evaluate as true, so the initializer modifier could be called repeatedly. The attacker reinitialized the Governance, Staking, and DelegateManagerV2 contracts, created erroneous delegations, passed governance proposal #85, and moved 18,564,497 AUDIO from the community treasury.

Audius identified the issue and deployed mitigation and contract patches the same day.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.