AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ruPubblicato 2026-07-31Pubblicato ultima volta 2026-07-31

Introduzione

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.

This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.

This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.

What Did AFX Trade Announce in Its Update?

The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".

The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.

However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.

Where Did the Stolen $24 Million Go?

The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.

Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.

AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.

Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.

How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?

A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.

The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.

Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.

The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.

By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.

A Major Single Loss in a Year Full of Many Smaller Ones

The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

Cryptocurrency losses by quarter. Source: TRM Labs.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.

AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.

Domande pertinenti

QWhen does AFX Trade plan to present its 'good faith plan' and what triggered this announcement?

AAFX Trade plans to present its 'good faith plan' on Monday, August 3. The announcement was triggered by a security incident where the platform lost over $24 million due to a breach in its exchange trade engine mechanism.

QAccording to the article, how did the attacker initially compromise the AFX Trade system?

AThe attack began around July 9 when a developer was contacted on Telegram by someone posing as a representative of Oddium Lab offering part-time work. The developer was tricked into cloning a repository that contained a malicious hook in the .git/config file. This hook deployed a first-stage malware onto the workstation when branches were switched.

QWhat was the final method used by the attacker to steal the funds from AFX Trade?

AThe attacker penetrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that drained the assets. The company stated the exploit was not a smart contract vulnerability but a 'vulnerability of trust.'

QHow does the AFX Trade breach fit into the broader trend of crypto losses in 2026 according to TRM Labs data?

AWhile 2026 saw a record 207 individual hacks in the first half, total losses fell to $972 million. Infrastructure and operational breaches, like the one at AFX Trade, accounted for only about 15% of incidents but were responsible for roughly 76% of the total money lost.

QWhat offer did Ken S., AFX Trade's Growth Lead, make to the attacker?

AKen S. offered to let the attacker keep 30% of the stolen funds as a 'white hat' bounty if they returned the remaining 70%.

Letture associate

Has Bitcoin Bottomed, or Is a 'Shakeout' Approaching? What's the Situation with XRP?

Cryptocurrency analytics platform Santiment shared key insights on Bitcoin and altcoin markets, highlighting significant signals from on-chain data. Analysis shows Bitcoin's 365-day MVRV ratio has fallen to -26%, indicating substantial losses for long-term holders, a level historically associated with market bottom formations and long-term buying opportunities. While short-term MVRV is near breakeven, suggesting no clear directional signal, the annual perspective points to a bottom before bullish cycles. On-chain data reveals divergent behavior: large wallets (10-10,000 BTC) have been accumulating, adding ~18,500 BTC in 10 days, while smaller retail investors continue buying dips. Analysts caution that high retail demand can sometimes create a risk of a final market shakeout or correction. The altcoin market shows a mixed picture. Ethereum's 365-day MVRV is around -33%, but recent monthly gains combined with overly optimistic social sentiment pose a short-term correction risk. XRP is in oversold territory with 30-day and 365-day MVRVs at -57.5% and -45.5% respectively, signaling potential for a strong mid-to-long term rebound. Social activity and optimism are rising for Solana, while investor sentiment remains calmer towards Cardano. Future direction for Bitcoin and altcoins depends not only on on-chain metrics but also on macroeconomic and regulatory developments. The Federal Reserve's interest rate decision and upcoming policy rulings are increasing market volatility expectations, while uncertainty around the U.S. Congressional clarity process continues to pressure pricing. *This is not investment advice.

cryptonews.ru1 h fa

Has Bitcoin Bottomed, or Is a 'Shakeout' Approaching? What's the Situation with XRP?

cryptonews.ru1 h fa

Bank of Korea Reveals Results of Tokenized Deposit Testing

The Bank of Korea has announced the results of its pilot test for tokenized deposits. Involving 28 central banks and international financial organizations, the project saw participation from major South Korean banks including KB Kookmin Bank, NH NongHyup Bank, Shinhan Bank, Woori Bank, and Hana Bank. Transactions, from payment orders to final settlement, were completed in real time, averaging just 80 seconds. The test involved 30 transactions across 17 different scenarios—such as corporate and interbank transfers—and was conducted in six currencies, including the Korean won, US dollar, and euro, with a total transaction value reaching approximately $995,000. The central bank reported that the platform operated stably throughout, despite being only partially connected to the existing banking infrastructure. Settlements using tokenized deposits were executed seamlessly, quickly, and transparently. An internal transfer of 20 million won (about $13,890) between NH NongHyup Bank and Shinhan Bank was also successfully processed via the Project Agora platform, which involved connecting to the Bank of Korea's CBDC test platform, Project Hangang. Additionally, KB Kookmin Bank and Japan's MUFG Bank tested cross-border payments using these deposit tokens—digital certificates issued by commercial banks within the pilot, not directly by the central bank. The Bank of Korea plans to continue testing payments with tokenized deposits. This follows last year's pledge by South Korean authorities to tighten regulations for won-based stablecoins, which will require approval from both the central bank and the Financial Services Commission.

cryptonews.ru3 h fa

Bank of Korea Reveals Results of Tokenized Deposit Testing

cryptonews.ru3 h fa

Trading

Spot
活动图片