AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ruPublished on 2026-07-31Last updated on 2026-07-31

Abstract

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.

This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.

This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.

What Did AFX Trade Announce in Its Update?

The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".

The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.

However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.

Where Did the Stolen $24 Million Go?

The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.

Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.

AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.

Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.

How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?

A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.

The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.

Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.

The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.

By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.

A Major Single Loss in a Year Full of Many Smaller Ones

The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

Cryptocurrency losses by quarter. Source: TRM Labs.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.

AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.

Related Questions

QWhen does AFX Trade plan to present its 'good faith plan' and what triggered this announcement?

AAFX Trade plans to present its 'good faith plan' on Monday, August 3. The announcement was triggered by a security incident where the platform lost over $24 million due to a breach in its exchange trade engine mechanism.

QAccording to the article, how did the attacker initially compromise the AFX Trade system?

AThe attack began around July 9 when a developer was contacted on Telegram by someone posing as a representative of Oddium Lab offering part-time work. The developer was tricked into cloning a repository that contained a malicious hook in the .git/config file. This hook deployed a first-stage malware onto the workstation when branches were switched.

QWhat was the final method used by the attacker to steal the funds from AFX Trade?

AThe attacker penetrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that drained the assets. The company stated the exploit was not a smart contract vulnerability but a 'vulnerability of trust.'

QHow does the AFX Trade breach fit into the broader trend of crypto losses in 2026 according to TRM Labs data?

AWhile 2026 saw a record 207 individual hacks in the first half, total losses fell to $972 million. Infrastructure and operational breaches, like the one at AFX Trade, accounted for only about 15% of incidents but were responsible for roughly 76% of the total money lost.

QWhat offer did Ken S., AFX Trade's Growth Lead, make to the attacker?

AKen S. offered to let the attacker keep 30% of the stolen funds as a 'white hat' bounty if they returned the remaining 70%.

Related Reads

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbit1h ago

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbit1h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbit1h ago

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbit1h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru7h ago

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru7h ago

Trading

Spot
活动图片