Author: Gu Yu, ChainCatcher
Today, the cross-chain bridge of decentralized perpetual contract exchange AFX was hacked, with over $24 million in assets stolen. Judging from the TVL displayed on Defillama, this amount is equivalent to the entire protocol being drained.
After the incident, AFX posted on X stating that they are working closely with leading security companies, ecosystem partners, exchanges, and relevant authorities to monitor fund flows and support the ongoing investigation.
I. Audit Report Full of Holes
However, AFX's painful lesson seems to have been foreshadowed. The project officially launched its mainnet in May and released an audit report on June 3rd. Following today's theft, multiple security professionals discovered significant issues with this report.
In the report, security audit firm Zellic stated they found 11 issues, including two critical ones, one with high impact, and six with medium impact.
"Given that this audit only covered a subset of the components constituting the bridge protocol and lacked test coverage for all security-critical paths, this is particularly important. This not only limited our ability to verify correctness but also our ability to maintain the system's security for AFX in the future. Furthermore, a crucial factor necessitating a re-audit is that we did not have the ability to run or interact with it in a live or local environment. This severely limited our ability to verify functionality, explore edge cases, and assess system behavior beyond static review," Zellic wrote in the conclusion.

According to Zellic's disclosure, the code they could access and verify only covered part of the bridge protocol's components, unable to cover the complete asset cross-chain process or be tested in a real operational environment. This means that for the bridge's most core critical paths such as asset custody, signature verification, and permission control, the audit firm could not provide a complete conclusion.
Zellic also specifically warned that even if the project team completed vulnerability fixes based on the report, the audit firm could not confirm whether these fixes were correctly implemented, let alone guarantee that new vulnerabilities would not be introduced during the fix process. This means that the report cannot actually serve as proof that the bridge protocol is "secure"; it is more like a phased inspection result for part of the code.
For a cross-chain bridge managing tens of millions of dollars in assets, "incomplete audit scope" is itself a risk. When the audit firm cannot confirm the entire system's security boundaries, users can hardly make judgments about the protocol's true security.
Regarding this, Taylor Monahan, Chief Product Manager of MetaMask and founder of MyEtherWallet and MyCrypto, posted on X saying AFX's cross-chain bridge audit report is "terrifying," with a large number of "confirmed" issues not being fixed, and expressed extreme confusion about users transferring over $24 million into the protocol.

"This audit strongly points to a team that fundamentally doesn't care about being responsible for a 'not-quite-actually M of N system'. Unhandled edge cases? No problem. Manual manipulation of user funds? No problem. Complete reliance on team intervention to prevent being robbed? No problem."
Taylor Monahan speculated that AFX likely has all validators and keys on the same system, or controlled by a single individual.
II. Parent Company Suspected to be Phemex
ChainCatcher's further research into the AFX team found that the project appears to have close ties with cryptocurrency exchange Phemex, and Phemex is likely its parent company.
The intricate connections among team members are supporting evidence. The X account of AFX's Growth Lead, Ken, previously listed his bio as "Head of Listing @phemex_official," one of the most core functional positions at any exchange.

Another AFX team member followed by the official AFX X account, Damon, although lacking more public profile information, after creating his X account and following the AFX account four months ago, also followed at least three X accounts of Phemex exchange team members.

Furthermore, the official Phemex exchange blog published multiple articles promoting AFX, such as "Unlock Your Strength: Discover Why AFX Protocol Transforms Lives", "The Philosophy of Anti-Fragility: Why AFX Protocol Matters", "Dive into the Multi-Asset Perps Revolution!", "Top 5 Perpetual DEXs to Watch in 2026". In the last article, AFX exchange was ranked ahead of other Perp DEXs like Hyperliquid.

Currently, the aforementioned articles have been deleted from the Phemex official website, but links to these articles still appear in Google search results when searching by title.
Another piece of associative evidence is that the logos of the two projects have very similar thematic styles, both using a gradient color from fluorescent green to cyan-green, paired with a pure black background. The visual atmosphere and color tone orientation are almost identical, which may also reflect that they share the same design team.

Considering team backgrounds, official historical promotion, brand design, and public operational traces, AFX and Phemex appear to have connections far beyond ordinary ecosystem partners.
The most "chilling" issue is that Phemex exchange was also hacked for over $70 million in January 2025, with external analysis at the time suggesting it was likely the work of North Korean hackers. At that time, the Phemex team stated that user assets would not be affected, the platform would bear the losses from the incident, and normal withdrawal processes were soon restored.
During the launch of the AFX product, Phemex clearly prepared risk isolation in advance, with no public association between the two in terms of brand, equity, etc. However, their intricate and close relationship cannot be completely concealed.
Now, the tragedy of losing tens of millions of dollars has happened again. Whether this is North Korean hackers repeating their old tricks or an internal setup for harvesting remains to be seen with more evidence and analysis.





