Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    China hypes its CBDC as tariff war threatens yuan

    July 31, 2026

    AI Agents in Web3: The Future of Autonomous Blockchain Systems

    July 31, 2026

    AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack

    July 31, 2026
    Facebook X (Twitter) Instagram
    Block Buzz News
    • Bitcoin
    • Coinbase
      • Litecoin
      • Altcoins
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Block Buzz News
    Home » AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack
    Crypto

    AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack

    James WilsonBy James WilsonJuly 31, 2026No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    AFX has announced that it has prepared a goodwill plan for users affected by last week’s $24.15 million bridge exploit, with the recovery proposal scheduled for release on Aug. 3.

    Summary

    • AFX will announce a goodwill plan for users affected by its $24.15 million bridge exploit on Aug. 3.
    • The protocol said its investigation found the attack began with a social engineering campaign that compromised internal development infrastructure.
    • AFX said the exploit targeted its own custody bridge and did not affect Arbitrum’s native bridge.
    • The protocol has rebuilt key infrastructure and introduced additional security measures while recovery efforts continue.

    According to an announcement shared by AFX, the decentralized derivatives protocol is finalizing a goodwill plan following the July 22 security incident and will publish the details on Monday, Aug. 3. The team said investors, employees and early supporters had all been affected by the attack and asked the community to remain patient while it completes the final proposal.

    We want to share a brief update with the community.

    A goodwill plan is currently in process following the recent security incident, and will be unveiled on Monday August 3rd. AFX investors, the team, and early supporters are all deeply affected by the situation so please bear…

    — AFX Trade (@AFX_XYZ) July 31, 2026

    The update comes after AFX completed its technical investigation into the exploit, which resulted in the theft of about 24.15 million USDC from an AFX-operated custody bridge. The protocol has not yet disclosed how compensation or recovery will be structured, but said its next announcement will focus on the goodwill plan.

    Earlier public statements confirmed the exploit targeted infrastructure operated by AFX rather than Arbitrum’s native bridge. At the time, blockchain security firm Blockaid and the Arbitrum team investigated the incident, while Offchain Labs co-founder Steven Goldfeder said the suspicious transaction originated from a third-party protocol instead of Arbitrum’s core bridge.

    AFX says attack started with a developer

    In a detailed post-mortem released after the incident, AFX said the breach originated from a social engineering campaign against one of its developers rather than a vulnerability in its smart contracts or blockchain infrastructure. According to the protocol, the attacker posed as a recruiter from a company called Oddium Lab on July 9 and convinced the developer to clone what appeared to be a legitimate software repository.

    AFX said the repository contained a malicious Git configuration that executed a hidden payload during a routine Git workflow, giving the attacker an initial foothold inside the developer’s workstation. Using the compromised device, the attacker gradually expanded access across internal development systems before downloading project source code several days later.

    The investigation said the attacker later uploaded a malicious Groovy plugin into the protocol’s JFrog artifact repository, obtaining remote code execution inside the software delivery environment. According to AFX, repeated out-of-memory events on the JFrog server were initially treated as operational problems with assistance from the vendor, allowing the malicious plugin to survive multiple restarts without triggering a security response.

    Forensic analysis later found that the attacker had replaced system binaries with trojanized versions, injected malicious shared libraries and attempted to erase security logs before portions of the malware crashed. SELinux logs captured outbound command-and-control traffic, shell execution and in-memory code execution that became important evidence during the investigation, according to the report.

    Validator compromise enabled the bridge theft

    The protocol said the attacker eventually pivoted from the compromised development environment into its operational infrastructure using an internal Ansible-based management service that already held privileged access to validator nodes. Rather than stealing new credentials or exploiting an external service, the attacker used existing trust relationships to deploy malicious payloads across a subset of validators.

    AFX said the infected validator nodes downloaded a second-stage payload from a remote server before interfering with consensus-message handling. At 9:27 p.m. UTC on July 22, the affected validators co-signed a bridge transaction that transferred roughly 24.15 million USDC from the AFX-operated custody bridge.

    The protocol said its investigation found no evidence that the Arbitrum network or Arbitrum’s native bridge had been compromised. The attack remained confined to infrastructure managed by AFX, matching statements previously issued by Offchain Labs and Blockaid during the initial response.

    On-chain investigators later tracked the stolen USDC after it moved from Arbitrum to Ethereum, where the proceeds were converted into approximately 12,467 ETH. At the time of the initial investigation, no public reports confirmed that any portion of the stolen assets had been recovered.

    Investigation points to supply chain compromise

    According to AFX, the incident demonstrated that software supply chain attacks can bypass blockchain security without exploiting smart contracts directly. The protocol concluded that the attack relied on trusted development tools, internal deployment systems and validator infrastructure instead of weaknesses in on-chain code.

    The report said the protocol has rebuilt affected infrastructure, rotated operational credentials, increased monitoring sensitivity and migrated production systems into a more isolated environment with zero-trust segmentation. Additional work planned over the coming months includes stronger behavioral monitoring, mandatory security reviews before restarting production services, expanded threat-hunting exercises and employee training against social engineering attacks.

    Based on forensic evidence, attack techniques and infrastructure observed during the investigation, AFX said its findings are consistent with independent attribution linking the incident to UNC4899, also known as TraderTraitor, a DPRK-linked threat group tracked by Mandiant, Microsoft Threat Intelligence, the FBI and CISA. The protocol said it continues working with external security partners to trace the stolen assets and support ongoing response efforts.

    Off-chain attacks have surfaced in multiple DeFi exploits

    The latest findings add to a series of incidents in which protocols have concluded that attackers compromised supporting infrastructure instead of exploiting flaws in smart contracts.

    On July 30, Ostium said its investigation into a separate 23.75 million USDC exploit found that unauthorized access to off-chain infrastructure allowed fraudulent BTC-USD price reports to drain funds from its liquidity vault, while its smart contracts and governance multisigs remained uncompromised. 

    Earlier this month, Singapore-based stablecoin payments firm Triple-A also disclosed unauthorized access to treasury wallets holding company-owned digital assets, although it said customer funds and payment operations were unaffected.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    Wintermute says 72% of spot OTC flow was institutional

    July 31, 2026

    Senator Schumer bill targets Trump’s $1.4B crypto income

    July 31, 2026

    Google backs $15B Anthropic data center in Texas

    July 31, 2026

    What is in the merged CLARITY Act text, and what changed

    July 31, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Sui’s 1.72 bugs caused three outages before foundation rolled out major fix

    June 1, 2026

    Web3 is dead? Kyle Samani says only DeFi and DePIN remain

    June 1, 2026

    Gnosis Pay exploit tied to Zodiac delay module as users exit

    June 1, 2026

    How the GENIUS Act made USDC wall street’s stablecoin

    June 1, 2026
    Don't Miss
    Coinbase

    China hypes its CBDC as tariff war threatens yuan

    By John SmithJuly 31, 2026

    As a way to project confidence into FX markets amid trade wars, China defended its…

    AI Agents in Web3: The Future of Autonomous Blockchain Systems

    July 31, 2026

    AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack

    July 31, 2026

    SEC wants to settle with Ripple, drops Helium case

    July 31, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    BlockBuzzNews: Your daily dose of the latest in cryptocurrency trends, insights, and updates!

    Our Picks

    China hypes its CBDC as tariff war threatens yuan

    July 31, 2026

    AI Agents in Web3: The Future of Autonomous Blockchain Systems

    July 31, 2026

    AFX schedules Aug. 3 goodwill plan following $24.15M bridge hack

    July 31, 2026
    Most Popular

    Sui’s 1.72 bugs caused three outages before foundation rolled out major fix

    June 1, 2026

    Web3 is dead? Kyle Samani says only DeFi and DePIN remain

    June 1, 2026

    Gnosis Pay exploit tied to Zodiac delay module as users exit

    June 1, 2026

    Type above and press Enter to search. Press Esc to cancel.