• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
AFX exploit

Fake recruiter tricked AFX developer into $24.15 million hack, investigation finds

07/31/2026
TER Gold-Backed Token Surges Into Spotlight With Bold Launch on Solana

3iQ wins first outside mandate to manage Bhutan’s sovereign Bitcoin holdings

07/31/2026
Bitcoin extortion scam

China Business Journal warns firms over fake-reporter Bitcoin extortion scam

07/31/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
AFX exploit

Fake recruiter tricked AFX developer into $24.15 million hack, investigation finds

07/31/2026
TER Gold-Backed Token Surges Into Spotlight With Bold Launch on Solana

3iQ wins first outside mandate to manage Bhutan’s sovereign Bitcoin holdings

07/31/2026
Bitcoin extortion scam

China Business Journal warns firms over fake-reporter Bitcoin extortion scam

07/31/2026
Friday, July 31, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Breaking News

Fake recruiter tricked AFX developer into $24.15 million hack, investigation finds

As investigators uncover how attackers infiltrated internal systems rather than blockchain infrastructure, AFX prepares a recovery proposal for users impacted by the multimillion-dollar breach.

by Elizabeth Omotoke
34 minutes ago
in Breaking News
Reading Time: 5 mins read
0
AFX exploit

AFX exploit

Share on FacebookShare on Twitter

AFX will announce a compensation plan on Aug. 3 for users affected by the $24.15 million exploit of its Arbitrum-based custody bridge, the decentralized derivatives protocol said this week. A forensic investigation traced the July 22 breach to an attacker who posed as a recruiter to trick a developer into installing malicious code, not a flaw in AFX’s smart contracts.

AFX said investors, employees, and early supporters were all affected by the breach and asked the community to remain patient as it finalizes the recovery proposal. While the protocol has yet to reveal the exact compensation framework, the upcoming announcement is expected to outline how affected users will be supported following one of the largest security incidents involving an Arbitrum-based protocol this year.

The attack, which resulted in the theft of approximately 24.15 million USDC, was confined to an AFX-operated custody bridge. The protocol emphasized that Arbitrum’s native bridge was never compromised, echoing earlier findings from blockchain security experts.

“The suspicious transaction originated from a third-party protocol rather than the Arbitrum bridge,” said Steven Goldfeder, co-founder of Offchain Labs, during the initial investigation.

Social engineering campaign triggered the AFX exploit

The completed investigation revealed that the AFX exploit began with an elaborate social engineering operation instead of a flaw in blockchain technology.

According to AFX’s post-mortem report, the attacker contacted one of the protocol’s developers on July 9, posing as a recruiter representing a company called Oddium Lab. The developer was persuaded to clone what appeared to be a legitimate software repository.

Unknown to the victim, the repository contained a malicious Git configuration that silently executed hidden code during a routine Git workflow. That initial compromise allowed the attacker to establish access to the developer’s workstation before gradually expanding privileges throughout AFX’s internal development infrastructure.

Investigators said the attackers later extracted project source code and escalated the breach further by uploading a malicious Groovy plugin into the protocol’s JFrog artifact repository, enabling remote code execution within AFX’s software delivery environment.

Repeated out-of-memory events on the JFrog server were initially treated as operational issues while engineers worked alongside the vendor, allowing the malicious plugin to remain active through multiple restarts without triggering immediate security alerts.

Forensic investigators later discovered that system binaries had been replaced with trojanized versions, malicious shared libraries had been injected into production systems, and attempts had been made to erase security logs. Fortunately, SELinux logs captured valuable evidence, including outbound command-and-control traffic and in-memory code execution that proved critical to reconstructing the attack timeline.

Validator compromise enabled $24.15 million bridge theft

After gaining deep access to AFX’s development environment, attackers moved laterally into the protocol’s operational infrastructure through an internal Ansible-based management service that already possessed privileged access to validator nodes.

Rather than exploiting newly discovered vulnerabilities or stealing fresh credentials, the attackers abused existing trust relationships within AFX’s infrastructure to distribute malicious payloads across several validator nodes.

AFX said the compromised validators downloaded a second-stage payload before interfering with consensus message processing.

At approximately 9:27 p.m. UTC on July 22, the affected validators co-signed a fraudulent bridge transaction that transferred roughly 24.15 million USDC from the AFX-operated custody bridge.

Following the theft, blockchain investigators tracked the stolen funds as they moved from Arbitrum to Ethereum, where they were converted into approximately 12,467 ETH. As of the latest update, no public confirmation has been provided indicating that any of the stolen assets have been recovered.

During the incident response, blockchain security company Blockaid worked alongside the Arbitrum team to analyze the breach.

AFX reiterated that the AFX exploit never impacted Arbitrum itself, reinforcing conclusions previously shared by Offchain Labs and Blockaid.

 Investigation highlights growing software supply chain risks

AFX concluded that the incident demonstrates how modern attackers increasingly target software supply chains and operational infrastructure instead of directly attacking blockchain protocols.

According to the investigation, trusted developer tools, deployment systems, and validator infrastructure became the primary attack vectors, allowing cybercriminals to bypass traditional blockchain security protections without exploiting smart contracts.

In response, AFX said it has rebuilt affected infrastructure, rotated operational credentials, strengthened monitoring capabilities, and migrated production services into a more isolated zero-trust environment.

The protocol also plans to introduce additional defensive measures over the coming months, including expanded threat-hunting exercises, mandatory security reviews before restarting production systems, enhanced behavioral monitoring, and broader employee training focused on identifying sophisticated phishing and social engineering attempts.

AFX further stated that forensic evidence, attack infrastructure, and observed tactics are consistent with activity attributed to UNC4899, also known as TraderTraitor, a North Korea-linked cyber threat group tracked by Mandiant, Microsoft Threat Intelligence, the FBI, and CISA.

The protocol said it continues collaborating with external cybersecurity partners to trace the stolen cryptocurrency and assist ongoing investigations.

Off-chain infrastructure becoming a growing DeFi security concern

The AFX exploit reflects a broader trend emerging across decentralized finance, where attackers increasingly compromise supporting infrastructure rather than blockchain code itself.

Only days after the AFX incident, decentralized trading protocol Ostium disclosed that unauthorized access to off-chain infrastructure enabled attackers to manipulate BTC-USD price reports, leading to the loss of 23.75 million USDC from its liquidity vault. Ostium noted that neither its smart contracts nor governance multisignature wallets had been compromised.

Similarly, Singapore-based stablecoin payments company Triple-A recently reported unauthorized access to treasury wallets containing company-owned digital assets, although it stressed that customer funds and payment operations remained secure.

These incidents illustrate how security challenges are expanding beyond smart contracts into development pipelines, validator infrastructure, deployment systems, and internal operational environments.

With the AFX exploit investigation now complete, attention will turn to the protocol’s promised goodwill plan scheduled for Aug. 3. Community members are awaiting details on how affected users will be compensated, while the incident serves as another reminder that even robust blockchain protocols remain vulnerable when trusted off-chain systems become compromised.

As decentralized finance continues to mature, cybersecurity experts increasingly argue that protecting development infrastructure, software supply chains, and employee workflows is becoming just as important as securing smart contracts themselves. The AFX exploit may ultimately become another defining example of how the industry’s threat landscape is rapidly evolving.

Tags: AFXBlockchain Securitycrypto exploitcryptocurrency crimecryptocurrency hackCryptocurrency Newscybercrimecybersecuritydigital assetsfake recruiter scamincident investigationphishing attacksmart contract securitysocial engineeringweb3 security
Share196Tweet123
Elizabeth Omotoke

Elizabeth Omotoke

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
AFX exploit

Fake recruiter tricked AFX developer into $24.15 million hack, investigation finds

07/31/2026
TER Gold-Backed Token Surges Into Spotlight With Bold Launch on Solana

3iQ wins first outside mandate to manage Bhutan’s sovereign Bitcoin holdings

07/31/2026
Bitcoin extortion scam

China Business Journal warns firms over fake-reporter Bitcoin extortion scam

07/31/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.