AFX Bizarre Theft Case: Audit Report Full of Holes, Suspected Parent Company is Crypto Exchange Phemex

链捕手Publicado a 2026-07-24Actualizado a 2026-07-24

Resumen

The decentralized perpetual exchange AFX suffered a hack on its cross-chain bridge, resulting in the theft of over $24 million, effectively draining the protocol's TVL. Following the incident, scrutiny fell on a security audit report released in early June by firm Zellic. The report itself raised significant red flags, stating it only covered part of the bridge's components, lacked testing of critical security paths, and was conducted without access to a live or local environment for proper validation. Prominent figures, including MetaMask's Taylor Monahan, criticized the report as alarming, noting numerous confirmed issues were left unaddressed and suggesting the team exhibited negligent security practices, potentially with a single point of control. Further investigation reveals strong ties between AFX and the centralized exchange Phemex. Key evidence includes a core AFX team member's previous role as Phemex's Head of Listing, overlapping social connections, Phemex's now-deleted blog posts actively promoting AFX, and nearly identical brand aesthetics. Notably, Phemex itself experienced a major $70+ million hack in January 2025, attributed at the time to North Korean hackers. The close association between the two entities, coupled with AFX's deeply flawed audit and subsequent major breach, raises serious questions about security standards and potential internal risks, leaving the true nature of the incident—whether another external attack or an internal scheme—unclear.

Author: Gu Yu, ChainCatcher

Today, the cross-chain bridge of decentralized perpetual contract exchange AFX was hacked, with over $24 million in assets stolen. Judging from the TVL displayed on Defillama, this amount is equivalent to the entire protocol being drained.

After the incident, AFX posted on X stating that they are working closely with leading security companies, ecosystem partners, exchanges, and relevant authorities to monitor fund flows and support the ongoing investigation.

I. Audit Report Full of Holes

However, AFX's painful lesson seems to have been foreshadowed. The project officially launched its mainnet in May and released an audit report on June 3rd. Following today's theft, multiple security professionals discovered significant issues with this report.

In the report, security audit firm Zellic stated they found 11 issues, including two critical ones, one with high impact, and six with medium impact.

"Given that this audit only covered a subset of the components constituting the bridge protocol and lacked test coverage for all security-critical paths, this is particularly important. This not only limited our ability to verify correctness but also our ability to maintain the system's security for AFX in the future. Furthermore, a crucial factor necessitating a re-audit is that we did not have the ability to run or interact with it in a live or local environment. This severely limited our ability to verify functionality, explore edge cases, and assess system behavior beyond static review," Zellic wrote in the conclusion.

According to Zellic's disclosure, the code they could access and verify only covered part of the bridge protocol's components, unable to cover the complete asset cross-chain process or be tested in a real operational environment. This means that for the bridge's most core critical paths such as asset custody, signature verification, and permission control, the audit firm could not provide a complete conclusion.

Zellic also specifically warned that even if the project team completed vulnerability fixes based on the report, the audit firm could not confirm whether these fixes were correctly implemented, let alone guarantee that new vulnerabilities would not be introduced during the fix process. This means that the report cannot actually serve as proof that the bridge protocol is "secure"; it is more like a phased inspection result for part of the code.

For a cross-chain bridge managing tens of millions of dollars in assets, "incomplete audit scope" is itself a risk. When the audit firm cannot confirm the entire system's security boundaries, users can hardly make judgments about the protocol's true security.

Regarding this, Taylor Monahan, Chief Product Manager of MetaMask and founder of MyEtherWallet and MyCrypto, posted on X saying AFX's cross-chain bridge audit report is "terrifying," with a large number of "confirmed" issues not being fixed, and expressed extreme confusion about users transferring over $24 million into the protocol.

"This audit strongly points to a team that fundamentally doesn't care about being responsible for a 'not-quite-actually M of N system'. Unhandled edge cases? No problem. Manual manipulation of user funds? No problem. Complete reliance on team intervention to prevent being robbed? No problem."

Taylor Monahan speculated that AFX likely has all validators and keys on the same system, or controlled by a single individual.

II. Parent Company Suspected to be Phemex

ChainCatcher's further research into the AFX team found that the project appears to have close ties with cryptocurrency exchange Phemex, and Phemex is likely its parent company.

The intricate connections among team members are supporting evidence. The X account of AFX's Growth Lead, Ken, previously listed his bio as "Head of Listing @phemex_official," one of the most core functional positions at any exchange.

Another AFX team member followed by the official AFX X account, Damon, although lacking more public profile information, after creating his X account and following the AFX account four months ago, also followed at least three X accounts of Phemex exchange team members.

Furthermore, the official Phemex exchange blog published multiple articles promoting AFX, such as "Unlock Your Strength: Discover Why AFX Protocol Transforms Lives", "The Philosophy of Anti-Fragility: Why AFX Protocol Matters", "Dive into the Multi-Asset Perps Revolution!", "Top 5 Perpetual DEXs to Watch in 2026". In the last article, AFX exchange was ranked ahead of other Perp DEXs like Hyperliquid.

Currently, the aforementioned articles have been deleted from the Phemex official website, but links to these articles still appear in Google search results when searching by title.

Another piece of associative evidence is that the logos of the two projects have very similar thematic styles, both using a gradient color from fluorescent green to cyan-green, paired with a pure black background. The visual atmosphere and color tone orientation are almost identical, which may also reflect that they share the same design team.

Considering team backgrounds, official historical promotion, brand design, and public operational traces, AFX and Phemex appear to have connections far beyond ordinary ecosystem partners.

The most "chilling" issue is that Phemex exchange was also hacked for over $70 million in January 2025, with external analysis at the time suggesting it was likely the work of North Korean hackers. At that time, the Phemex team stated that user assets would not be affected, the platform would bear the losses from the incident, and normal withdrawal processes were soon restored.

During the launch of the AFX product, Phemex clearly prepared risk isolation in advance, with no public association between the two in terms of brand, equity, etc. However, their intricate and close relationship cannot be completely concealed.

Now, the tragedy of losing tens of millions of dollars has happened again. Whether this is North Korean hackers repeating their old tricks or an internal setup for harvesting remains to be seen with more evidence and analysis.

Preguntas relacionadas

QAccording to the article, what were the main issues identified with the AFX audit report from Zellic?

AThe Zellic audit report for AFX had significant limitations. It only covered part of the bridge protocol's components, lacked testing coverage for all security-critical paths, and was unable to run or interact with the system in a live or local environment. This severely restricted their ability to verify functionality, explore edge cases, and assess system behavior beyond static review. The report essentially could not confirm the overall security of the bridge.

QWhat criticism did Taylor Monahan level against the AFX team based on the audit findings?

ATaylor Monahan criticized the AFX team for appearing to fundamentally not care about responsibility for a system that was 'not quite a true M of N system.' She pointed out the team's disregard for unhandled edge cases, manual operation of user funds, and complete reliance on team intervention to prevent exploitation. She speculated that all validators and keys were likely on the same system or controlled by a single individual.

QWhat evidence does the article provide to suggest Phemex is the parent company of AFX?

AThe article provides several pieces of evidence linking AFX to Phemex: 1) AFX's growth lead, Ken, previously listed 'Head of Listing @phemex_official' in his X bio. 2) Another AFX team member, Damon, follows several Phemex staff accounts. 3) Phemex's official blog published multiple promotional articles about AFX (though later deleted). 4) The visual branding and logo designs of AFX and Phemex are strikingly similar in color scheme and style.

QWhat major security incident involving Phemex is mentioned in the article, and how is it contextually relevant?

AThe article mentions that Phemex suffered a theft of over $70 million in January 2025, which was widely attributed to North Korean hackers at the time. This is contextually relevant because it highlights a pattern of major security breaches associated with what appears to be the same corporate entity behind AFX, raising questions about their overall security practices and risk management.

QWhat was the estimated financial impact of the hack on the AFX protocol?

AThe hack on AFX's cross-chain bridge resulted in the theft of over $24 million in assets. According to data from Defillama, this amount was equivalent to the protocol's entire Total Value Locked (TVL), meaning the protocol was essentially drained empty.

Lecturas Relacionadas

The Verdict in Choi Tae-won's Divorce Case: Revealing the Inheritance Undercurrent Behind SK Hynix's Trillion-Won Empire

SK Group Chairman Chey Tae-won's high-profile divorce case, involving a record 1.38 trillion won settlement, has drawn attention to the succession plans for Korea's second-largest conglomerate, especially its crown jewel, SK hynix. Unlike traditional chaebol scripts centered on the eldest son, Chey's three children from his marriage to former President Roh Tae-woo's daughter, Roh Soh-yeong, are carving distinct, non-traditional paths. Eldest daughter Chey Yun-jung (b. 1989) is seen as the most evident successor. With a scientific and consulting background, she holds executive roles at SK bioscience and SK Inc.'s growth support department, focusing on future strategy and biopharma. Her marriage is to an AI infrastructure entrepreneur, not a traditional business alliance. Second daughter Chey Min-jung (b. 1991) took a unique route, voluntarily serving as a South Korean naval officer, including an anti-piracy deployment. She later worked on policy and strategy for SK hynix in Washington D.C. before co-founding an AI-driven healthcare startup. She married a former U.S. Marine Corps officer, connecting her to U.S. defense and policy circles—networks crucial for a global semiconductor giant. The only son, Chey In-geun (b. 1995), who studied physics like his father, worked briefly at SK E&S before joining McKinsey. Despite fitting the traditional "heir" profile as the eldest son, he remains silent and holds no public position or shares in SK, suggesting the old succession playbook is obsolete. As SK hynix's valuation soars, becoming a geopolitical asset in the AI era, the heirs' legitimacy is no longer automatic. They must prove themselves in fields like AI biotech, global policy, and strategic consulting. Their marriages also reflect new elite networks in tech and defense, not old political alliances. Their inheritance is the complex challenge of navigating a globalized, tech-driven world, not just a corporate throne.

marsbitHace 12 hora(s)

The Verdict in Choi Tae-won's Divorce Case: Revealing the Inheritance Undercurrent Behind SK Hynix's Trillion-Won Empire

marsbitHace 12 hora(s)

From OpenSea to OpenRouter: Is Alex Atallah Repeating His 'Exit at the Peak' Playbook?

From OpenSea to OpenRouter: Is Alex Atallah Repeating His "Exit at the Peak" Playbook? According to the Wall Street Journal, payments giant Stripe is in talks to acquire the AI model aggregation platform OpenRouter in a potential deal valuing the company near $100 billion. This would mark founder Alex Atallah's second creation of a company reaching a $100 billion valuation, following his co-founding of NFT marketplace OpenSea. OpenRouter, founded just over three years ago, has grown rapidly by acting as a unified gateway for developers to access over 400 AI models. It currently has about 10 million users and processes over 200 trillion tokens monthly. While the platform's annualized revenue is around $50 million, its valuation has skyrocketed from $1.3 billion in March 2026. The potential acquisition by Stripe, a company OpenRouter's founder once likened it to, represents a major expansion into AI infrastructure for the payments leader. This move echoes Atallah's previous timing with OpenSea, where he departed before the NFT market's significant downturn. For OpenRouter, selling now may be strategic. Despite its scale, its business model—charging a 5-5.5% fee on AI inference calls—faces pressure from competition, open-source models, and potential price wars among model providers, limiting its profitability narrative for an IPO. A key asset for potential acquirers like Stripe is OpenRouter's vast repository of real-world AI usage data, which offers unique insights into model performance and developer preferences that are difficult to replicate. Whether this potential deal signifies a new valuation benchmark for AI infrastructure or another market peak signal remains to be seen.

链捕手Hace 12 hora(s)

From OpenSea to OpenRouter: Is Alex Atallah Repeating His 'Exit at the Peak' Playbook?

链捕手Hace 12 hora(s)

Trading

Spot
活动图片