AFX Trade Promises to Present "Goodwill Plan" on August 3 Following $24 Million Loss Incident

cryptonews.ru發佈於 2026-07-31更新於 2026-07-31

文章摘要

AFX Trade, a cryptocurrency platform, announced it will present a "goodwill plan" on August 3rd, following a security incident on July 22nd that resulted in a loss of $24.15 million. The company's brief update offered no specific details on compensation for affected users, investors, and employees, only urging calm while the team formulates next steps. The theft occurred from a USDC custody account on Arbitrum, with the stolen funds converted to Ethereum. Blockchain analysts traced the funds to a single wallet. AFX Trade and Arbitrum clarified the exploit targeted a third-party bridge, not Arbitrum's native bridge. An investigation revealed the attack began on July 9th with a social engineering scheme targeting a developer. The attacker then deployed malicious code within AFX's internal JFrog repository and infrastructure, eventually compromising bridge validators to authorize the fraudulent withdrawal. The company stated the exploit leveraged a "trust vulnerability," not a smart contract bug. AFX Trade's head of business development made an offer to the attacker, proposing they keep 30% of the funds as a white hat bounty if 70% is returned. The incident fits a 2026 trend identified by TRM Labs: while the number of crypto hacks hit a record, total losses decreased. However, infrastructure and operational breaches, though fewer, accounted for the majority of financial losses. The AFX breach is classified as an infrastructure incident involving private key compromise.

On Friday, July 31, AFX Trade informed its community that a "goodwill plan" for users would be published on Monday, August 3.

This could be a step towards compensating affected users; however, the update provided no information on what users should expect. The message urged for calm while the team develops next steps.

This came nine days after the platform lost over $24 million due to a breach in the commodity exchange mechanism.

What Did AFX Trade Announce in Its Update?

The update was brief and lacked specific details. The message was posted from AFX Trade's X account and read: "A customer-centric action plan following the recent security incident is currently being developed and will be presented on Monday, August 3".

The team added that the data leak had impacted investors, employees, and early sponsors, and shared a link to a Medium article containing a detailed analysis of what happened.

However, no figures, participation rules, or payout timelines were communicated, nor was it clarified whether this information would be published next Monday.

Where Did the Stolen $24 Million Go?

The theft occurred on July 22, with security firm Blockaid estimating the damage at $24.15 million. The funds were withdrawn from the $USDC custodial account managed by AFX on the Arbitrum platform.

Blockchain analysts from PeckShieldAlert stated that the perpetrator moved the stablecoins to Ethereum and converted them into 12,468 ETH, which ended up in a single wallet.

AFX Trade suspended its bridge after detecting the hack and stated that the vulnerability only affected the specific bridge involved. Arbitrum made a similar statement, with co-founder Steven Goldfeder adding that the network's native bridge "was not hacked or exploited in any way" and that the transaction causing the issue happened via a third-party protocol operating on the second layer.

Ken S., Head of Development at AFX Trade, made an offer to the perpetrator, stating they were willing to let them keep 30% of the funds as a reward for "white-hat" activity if they returned 70%.

How Did the Perpetrator Hack the AFX Trade $USDC Custody Bridge?

A detailed analysis of the incident published by AFX Trade traced its origin to July 9, when a developer was contacted via Telegram by a person claiming to be a representative of Oddium Lab and offering part-time work.

The developer was prompted to clone a repository that appeared to be a standard DEX aggregator repository. Changes were made to its .git/config file, allowing a malicious post-checkout hook to run at the moment of branch switching, thereby deploying a first-stage malicious program onto the workstation.

Following this, the perpetrator began operating inside the network, not on the blockchain. On July 16, they uploaded a malicious Groovy plugin, ops_maintenance.groovy, into AFX Trade's JFrog artifact repository, enabling them to execute code on that host.

The plugin also caused severe crashes due to memory shortages, which were interpreted as normal infrastructure issues, so engineers engaged JFrog's own support and restarted the machine, which discreetly reloaded the malware.

By July 22, the perpetrators had infiltrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that withdrew the assets. "They didn't exploit a smart contract vulnerability. They exploited a trust vulnerability," AFX wrote.

A Major Single Loss in a Year Full of Many Smaller Ones

The AFX data theft fits a pattern observed throughout the year. TRM Labs reported that in the first half of 2026, perpetrators carried out 207 separate hacks, a record for a six-month period.

Cryptocurrency losses by quarter. Source: TRM Labs.

However, total losses shrank to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational breaches accounted for only about 15% of incidents, but represented about 76% of the lost funds.

AFX is among the most severely affected. A separate tally showed AFX's damage at $24.15 million, alongside larger access control breaches such as $292 million at Kelp DAO and $280 million at Drift Protocol. DeFiLlama's Exploit Database classifies the AFX bridge outage as an infrastructure incident, with private key compromise being the cause—the same reason responsible for the bulk of dollar losses in 2026, even as the total number of exploits in other areas grows.

相關問答

QWhen does AFX Trade plan to present its 'good faith plan' and what triggered this announcement?

AAFX Trade plans to present its 'good faith plan' on Monday, August 3. The announcement was triggered by a security incident where the platform lost over $24 million due to a breach in its exchange trade engine mechanism.

QAccording to the article, how did the attacker initially compromise the AFX Trade system?

AThe attack began around July 9 when a developer was contacted on Telegram by someone posing as a representative of Oddium Lab offering part-time work. The developer was tricked into cloning a repository that contained a malicious hook in the .git/config file. This hook deployed a first-stage malware onto the workstation when branches were switched.

QWhat was the final method used by the attacker to steal the funds from AFX Trade?

AThe attacker penetrated the validator infrastructure, sent malicious code to target nodes, and used the compromised validators to co-sign a bridge call that drained the assets. The company stated the exploit was not a smart contract vulnerability but a 'vulnerability of trust.'

QHow does the AFX Trade breach fit into the broader trend of crypto losses in 2026 according to TRM Labs data?

AWhile 2026 saw a record 207 individual hacks in the first half, total losses fell to $972 million. Infrastructure and operational breaches, like the one at AFX Trade, accounted for only about 15% of incidents but were responsible for roughly 76% of the total money lost.

QWhat offer did Ken S., AFX Trade's Growth Lead, make to the attacker?

AKen S. offered to let the attacker keep 30% of the stolen funds as a 'white hat' bounty if they returned the remaining 70%.

你可能也喜歡

如何让自己变得让人工智能永远也无法取代

面对人工智能的冲击,许多人担心工作被取代。然而,真正的威胁在于个人对他人和系统的依赖,以及由此产生的“薪资奴役”——即为生存而从事无意义、枯燥的工作。摆脱这种困境的关键,不是抵制技术,而是成为拥有高自主性的“不可受雇”个体。 文章提出了成功抵御AI替代的五个核心要素:自主性(主动行动的能力)、品味(判断事物价值的经验)、说服力(让他人关注你工作的能力)、毅力(坚持并从错误中学习)和迭代(根据反馈持续改进)。这些能力无法仅通过理论学习获得,必须通过实践来培养。 要启动转变,首先要彻底改变环境,重塑身份认同。其次,应选择一个能获得真实、快速反馈的实践领域,例如创业。在众多技能中,内容创作(媒体)比编写代码更具优势,因为其价值是主观的,需要独特的审美和判断力,这正是AI目前难以完全复制的。 具体行动上,可以从三个步骤开始: 1. **挖掘原始素材**:反思自己长期痴迷的知识领域、轻松解决的难题或童年被压抑的兴趣,找到独特的个人经验。 2. **确立反向思考主轴**:找出你坚信但主流观点错误的地方,或行业内普遍忽视的“皇帝新衣”,形成独特的批判性视角。 3. **立即发布**:将前两步的思考融合,撰写并发布第一个核心内容(如帖子、视频),勇敢接受真实世界的反馈,并在此基础上持续学习和迭代。 最终,抵御AI的关键在于构建一份与自身身份深度契合的毕生事业,通过持续的内容创作和真实互动,建立无法被自动化取代的独特价值和影响力。行动,从今天发布第一个想法开始。

marsbit1 小時前

如何让自己变得让人工智能永远也无法取代

marsbit1 小時前

通过掷骰子离线保管比特币密钥:并非人人愿意为之

文章探讨了通过投掷骰子生成比特币钱包种子短语的安全方法及其现实挑战。核心观点如下: **1. 骰子提供物理熵源** 骰子结果由众多微小变量决定,理论上虽可预测,但实践中无法被攻击者复制或计算,从而提供高质量的随机性。每个六面骰子投掷约产生2.585比特熵,50次投掷即可满足典型12词助记词(128比特熵)的安全需求。 **2. Coldcard漏洞事件凸显手工熵源的价值** 近期Coldcard硬件钱包因固件漏洞导致其内部随机数生成器存在缺陷,致使约1128枚比特币被盗。但那些**完全**通过足量骰子投掷生成种子短语的用户未受此漏洞影响,因为他们的主密钥未使用有缺陷的生成器。 **3. 重要警示:手工种子并非万能保护** 安全研究员指出,即使用户使用骰子生成了安全的种子,若他们使用了Coldcard的其他功能(如生成纸钱包、克隆密钥、共享签名密钥、密码等),这些**衍生密钥**仍可能调用有漏洞的随机数生成器,从而存在风险。安全种子不保证设备生成的所有秘密都安全。 **4. 手工生成熵源的现实局限性** 尽管数学上可靠,但该方法对大多数用户并不友好: * **过程繁琐易错**:需投掷50-99次,精确记录,任何输入错误都会导致钱包完全不同。 * **引入新风险**:用户可能在记录、转换过程中泄露信息,或使用有偏的骰子/投掷方式。 * **用户体验差**:难以想象大规模推广需要用户手动投掷近百次骰子。安全措施需适应现实生活场景和普通用户的知识水平。 **5. 给用户的建议** 受影响的Coldcard用户应: * 更新固件至最新版。 * 检查是否使用过有漏洞的功能生成了次级密钥或密码,如有则需立即更换。 * 考虑采用多签方案,使用不同厂商的设备分散风险。 **结论**:手工投掷骰子生成熵源是技术娴熟用户的一个有效安全选项,但其过程复杂、容易出错,不适合作为主流用户的默认方法。长远目标是依赖安全、透明且无需专业知识的硬件/软件随机数生成方案。

cryptonews.ru4 小時前

通过掷骰子离线保管比特币密钥:并非人人愿意为之

cryptonews.ru4 小時前

交易

現貨
活动图片