AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ru發佈於 2026-07-31更新於 2026-07-31

文章摘要

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.

This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.

This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.

What Did AFX Trade Announce in Its Update?

The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".

The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.

However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.

Where Did the Stolen $24 Million Go?

The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.

Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.

AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.

Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.

How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?

A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.

The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.

Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.

The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.

By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.

A Major Single Loss in a Year Full of Many Smaller Ones

The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

Cryptocurrency losses by quarter. Source: TRM Labs.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.

AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.

相關問答

QWhen does AFX Trade plan to present its 'good faith plan' and what triggered this announcement?

AAFX Trade plans to present its 'good faith plan' on Monday, August 3. The announcement was triggered by a security incident where the platform lost over $24 million due to a breach in its exchange trade engine mechanism.

QAccording to the article, how did the attacker initially compromise the AFX Trade system?

AThe attack began around July 9 when a developer was contacted on Telegram by someone posing as a representative of Oddium Lab offering part-time work. The developer was tricked into cloning a repository that contained a malicious hook in the .git/config file. This hook deployed a first-stage malware onto the workstation when branches were switched.

QWhat was the final method used by the attacker to steal the funds from AFX Trade?

AThe attacker penetrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that drained the assets. The company stated the exploit was not a smart contract vulnerability but a 'vulnerability of trust.'

QHow does the AFX Trade breach fit into the broader trend of crypto losses in 2026 according to TRM Labs data?

AWhile 2026 saw a record 207 individual hacks in the first half, total losses fell to $972 million. Infrastructure and operational breaches, like the one at AFX Trade, accounted for only about 15% of incidents but were responsible for roughly 76% of the total money lost.

QWhat offer did Ken S., AFX Trade's Growth Lead, make to the attacker?

AKen S. offered to let the attacker keep 30% of the stolen funds as a 'white hat' bounty if they returned the remaining 70%.

你可能也喜歡

Wintermute:加密货币下一轮山寨季的赢家可能更少

加密货币做市商Wintermute指出,随着机构投资者将活动集中在更小范围的数字资产中,下一次山寨币季节的赢家可能会减少。 根据Wintermute 2026年上半年的场外交易报告,机构交易对手在其场外交易平台所有代币的现货流中占比达到创纪录的72%,高于2025年下半年的61%。报告发现,机构活动集中在更少的代币上,且在价格飙升后消退更快,这意味着未来的山寨币上涨可能更狭窄和更具选择性。机构偏好的资产流动性集中,而市场“长尾”部分的交易活动则减弱。 数据显示,从2024年上半年到2026年上半年,机构交易对手交易的独特代币数量仅增长24%,而零售客户增长了76%。此外,机构在某代币价格和成交量激增后的活跃度大约一天后就会减退,而零售活动通常会持续约三天。 这一发现与更广泛市场中资本正向更少的山寨币聚集的趋势相符。CryptoQuant数据表明,比特币利润向小型加密资产轮动的传统模式已基本消失,且以比特币计价的山寨币交易对成交量接近2021年以来的最低水平。同时,前十大非稳定币山寨币占据了非比特币、非稳定币市场约80.5%的市值。Kaiko的数据也显示,交易所交易呈现类似集中化,2025年7月前十大山寨币占山寨币交易量的63%。 行业观点认为,广泛的山寨币普涨正让位于选择性板块轮动,大量代币在争夺有限资金,而机构投资者仍专注于比特币、以太坊及代币化的现实世界资产。

cointelegraph20 分鐘前

Wintermute:加密货币下一轮山寨季的赢家可能更少

cointelegraph20 分鐘前

交易

現貨
活动图片