On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.
This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.
This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.
What Did AFX Trade Announce in Its Update?
The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".
The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.
However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.
Where Did the Stolen $24 Million Go?
The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.
Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.
AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.
Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.
How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?
A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.
The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.
Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.
The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.
By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.
A Major Single Loss in a Year Full of Many Smaller Ones
The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.
AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.





