An attacker removed 18,564,497.819999999999735541 AUDIO tokens from the Audius community treasury on July 23, 2022 after manipulating the music protocol’s Ethereum governance system. The successful transfer was recorded at 23:11:36 UTC. At 23:12:03 UTC, the entire amount was exchanged through Uniswap V2 for 704.177543861243828018 ETH.

The 27-second interval is a calculation from the two Ethereum transaction timestamps. It shows how quickly a governance compromise could become an irreversible asset transfer, but it does not by itself identify the attacker or establish a dollar loss. Ethereum records authenticate the transactions and quantities; the explanation of how the attacker acquired governance control came from Audius’s subsequent investigation.

Governance became the attack surface

The treasury transfer resulted from Audius governance Proposal 85. Audius later reported that the attacker changed protocol configuration, assigned an artificial amount of delegated AUDIO to attacker-controlled accounts and used the resulting voting weight to pass the proposal. The proposal transferred the community treasury to a contract controlled by the attacker.

A preceding attempt, Proposal 84, did not pass. In the successful sequence, Audius’s later reconstruction recorded a second erroneous delegation of 10 trillion AUDIO inside its staking and delegation contracts. That figure did not represent newly minted or circulating tokens. It was corrupted internal accounting used to manufacture enough voting power to approve Proposal 85.

The distinction matters. This was not a conventional private-key theft from an externally owned wallet, and it was not evidence that 10 trillion genuine AUDIO entered circulation. The attacker caused the protocol’s own governance machinery to authorize a real transfer by first corrupting the state from which voting power was calculated.

Execution value differed from quoted value

Contemporaneous reporting described the transferred tokens as carrying a quoted market value above $6 million, while the 704.18 ETH received was estimated at approximately $1.1 million around the transaction. Those figures are not equivalent measures. The first applied a market quotation to a large token balance; the second reflected the actual decentralized-exchange execution and then converted the ETH proceeds into dollars near the trade time.

AUDIO traded continuously across multiple venues, and the Uniswap sale itself moved through limited liquidity. Coinburn therefore treats 704.177543861243828018 ETH as the verified consideration and the dollar estimates only as contemporaneous approximations. The gap illustrates the limitation of multiplying a thinly traded token’s displayed price by a treasury-sized balance: quoted capitalization does not guarantee executable liquidity.

Why the incident mattered

Audius used token governance to administer contracts responsible for staking, delegation and treasury control. The July 23 exploit showed that decentralized voting procedures could offer little protection when the underlying contract state determining who could vote was itself vulnerable. Once counterfeit voting weight was accepted, proposal submission, approval and execution became tools of the attack rather than safeguards against it.

The episode also demonstrated the limits of security audits. Audius later disclosed that the affected contracts had received an OpenZeppelin audit before deployment and that separate subsequent changes had been reviewed by Kudelski Security. Audius said neither review detected the vulnerability. That did not establish that audits were valueless; it established that an audit was not a continuing guarantee against every interaction between customized proxy code and contract storage.

Later context: the initialization flaw

In a postmortem published on July 24, 2022, Audius attributed the compromise to a storage collision between its customized upgradeable proxy and initialization state. The collision allowed functions intended to run once to be invoked repeatedly. The attacker used those calls to alter governance, staking and delegation state.

Audius said it deployed blocking contracts to halt further activity, subsequently patched initialization storage and worked to restore the affected systems. Those remediation details were established after the July 23 transactions and are included as later context, not as information publicly confirmed before the exploit occurred.

Primary sourceAudius Governance Takeover Post-Mortem — July 23, 2022

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.