AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ru发布于2026-07-31更新于2026-07-31

文章摘要

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.

This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.

This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.

What Did AFX Trade Announce in Its Update?

The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".

The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.

However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.

Where Did the Stolen $24 Million Go?

The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.

Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.

AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.

Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.

How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?

A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.

The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.

Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.

The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.

By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.

A Major Single Loss in a Year Full of Many Smaller Ones

The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

Cryptocurrency losses by quarter. Source: TRM Labs.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.

AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.

相关问答

QWhen does AFX Trade plan to present its 'good faith plan' and what triggered this announcement?

AAFX Trade plans to present its 'good faith plan' on Monday, August 3. The announcement was triggered by a security incident where the platform lost over $24 million due to a breach in its exchange trade engine mechanism.

QAccording to the article, how did the attacker initially compromise the AFX Trade system?

AThe attack began around July 9 when a developer was contacted on Telegram by someone posing as a representative of Oddium Lab offering part-time work. The developer was tricked into cloning a repository that contained a malicious hook in the .git/config file. This hook deployed a first-stage malware onto the workstation when branches were switched.

QWhat was the final method used by the attacker to steal the funds from AFX Trade?

AThe attacker penetrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that drained the assets. The company stated the exploit was not a smart contract vulnerability but a 'vulnerability of trust.'

QHow does the AFX Trade breach fit into the broader trend of crypto losses in 2026 according to TRM Labs data?

AWhile 2026 saw a record 207 individual hacks in the first half, total losses fell to $972 million. Infrastructure and operational breaches, like the one at AFX Trade, accounted for only about 15% of incidents but were responsible for roughly 76% of the total money lost.

QWhat offer did Ken S., AFX Trade's Growth Lead, make to the attacker?

AKen S. offered to let the attacker keep 30% of the stolen funds as a 'white hat' bounty if they returned the remaining 70%.

你可能也喜欢

美国对伊朗支持比特币支付的加密服务Hormuz Safe实施制裁

美国财政部通过外国资产控制办公室(OFAC)对两家伊朗公司——波斯湾海上保险公司(PGMIC)和霍尔木兹安全海上服务局——实施制裁,指控其建立了一套通过加密货币支付数字海上保险来规避制裁的计划。同时,八艘船舶和八家被华盛顿指为伊朗“影子船队”组成部分的公司也受到限制。 OFAC称,伊朗政府建立了一个系统,强制要求商业船舶购买强制海上保险才能通过霍尔木兹海峡。伊朗于2026年5月正式启动霍尔木兹安全平台,允许使用比特币等加密货币支付保险单,预计该平台每年可带来高达100亿美元收入。美国当局认为,这种模式使伊朗政权能够获得额外收入并规避西方制裁。 美国财长斯科特·贝森特指责伊朗利用国际航运资助恐怖主义、侵略和伊斯兰革命卫队的镇压行动。OFAC强调,这些保险本应保护船舶免遭扣押等风险,但美方认为大部分风险是伊朗自身制造的。 此外,OFAC还对八家航运公司和油轮实施了制裁,指控其在违反国际限制的情况下运输伊朗石油及石油产品。自2026年初以来,OFAC已对超过100艘与伊朗“影子船队”相关的船舶实施了制裁。受制裁公司的资产将被冻结,且美国公司被禁止与其进行交易。此次制裁是在美伊外交接触的背景下实施的,有报道称伊朗尚未回应美国通过卡塔尔提出的重返谈判建议。

cryptonews.ru45分钟前

美国对伊朗支持比特币支付的加密服务Hormuz Safe实施制裁

cryptonews.ru45分钟前

“新一轮周期前的最后阶段”。比特币在八月将何去何从

《RBK-加密》指出,比特币在7月底从多年低点反弹超10%,但受访专家预计8月不会持续上涨,反而可能跌破6万美元。专家认为,历史趋势和宏观经济因素正在压制加密货币市场,8月将是“区间测试”月份,而非趋势逆转之时。 截至7月底,比特币交易价格约为6.35万美元,较2025年10月的历史高点12.62万美元下跌约50%。自6月初以来,其价格主要在6万至6.5万美元的狭窄区间内波动。 专家指出,比特币面临不利的宏观经济环境,包括美国高利率、持续通胀和高油价,这些因素共同构成压力。高利率使得国债等固定收益资产比加密货币更具吸引力,同时投资者也流向半导体和人工智能相关股票,加剧了资本竞争。比特币现货ETF在2024年上半年出现净流出54亿美元,仅6月就流出创纪录的45亿美元,7月的资金流入微乎其微。 历史数据也显示,8月对加密货币市场通常是弱势月份,2013-2025年间8月的平均收益率为1.12%,但中位数为负7.49%,表明下跌月份居多。美国关键的加密监管法案《CLARITY Act》迟迟未获通过,也增加了不确定性。 尽管如此,专家认为当前可能正处于新周期开始前的最后阶段。每次熊市约持续400天,当前环境适合长期积累比特币。多数专家预计8月比特币将在5.8万至6.8万美元区间震荡,关键支撑位在6-6.1万美元,若跌破5.8万可能下探5-5.5万美元。上涨至6.7万并突破6.8万阻力位的概率较低。部分观点认为,市场可能需等到今年第四季度才会出现更明确的趋势性运动。 专家建议投资者可考虑在比特币和强势项目上逐步建立头寸,但应避免 meme 币和新兴代币。长期来看,市场已处于不错的入场位置。

cryptonews.ru45分钟前

“新一轮周期前的最后阶段”。比特币在八月将何去何从

cryptonews.ru45分钟前

交易

现货
活动图片