AFX Trade bridge exploit drains $24.15 million on Arbitrum

AFX Trade bridge exploit drains $24.15 million on Arbitrum

AFX said it will unveil a goodwill plan on Aug. 3 after concluding the $24.15 million theft stemmed from a social-engineering-led compromise of its internal infrastructure, not Arbitrum’s native bridge.

ETH
USDC
ARB

Fact Check
Every element of the claim is corroborated by AFX's own primary sources and multiple independent reports. AFX's Medium post-mortem and its official X announcement confirm the Aug. 3 goodwill/recovery plan, the ~$24.15M USDC loss on July 22, 2026, the social-engineering-led compromise of internal infrastructure (developer workstation, supply chain, validator signing), and the explicit conclusion that AFX's own custody bridge—not Arbitrum's native bridge—was exploited. Independent outlets (crypto.news, Cryptopolitan) report identical figures and framing.
Summary

AFX Trade said it will publish a goodwill plan on Aug. 3 for users affected by the July 22 theft of about $24.15 million in USDC from its custody bridge. The protocol said investors, employees and early supporters were all affected. A post-mortem released by AFX said the breach began with a social engineering campaign against one of its developers on July 9, when an attacker posing as a recruiter from Oddium Lab convinced the developer to clone a malicious repository. AFX said the compromise spread from the developer’s workstation into internal development systems, then into its software delivery environment through a malicious Groovy plugin uploaded to its JFrog artifact repository. AFX said the attacker later moved into operational infrastructure through an internal Ansible-based management service with privileged access to validator nodes, allowing malicious payloads to be deployed across a subset of validators. At 9:27 p.m. UTC on July 22, the affected validators co-signed a bridge transaction that transferred roughly 24.15 million USDC from the AFX-operated custody bridge. The protocol said the attack was confined to infrastructure it managed and did not compromise Arbitrum’s network or native bridge, echoing earlier statements from Offchain Labs co-founder Steven Goldfeder and blockchain security firm Blockaid. On-chain investigators previously tracked the stolen funds from Arbitrum to Ethereum, where they were converted into about 12,467 ETH. AFX said the findings are consistent with independent attribution to UNC4899, also known as TraderTraitor, a DPRK-linked threat group tracked by Mandiant, Microsoft Threat Intelligence, the FBI and CISA. The protocol said it has rebuilt affected infrastructure, rotated credentials, tightened monitoring and moved production systems into a more isolated zero-trust environment while continuing asset-tracing and response efforts with external security partners.

Terms & Concepts
  • social engineering: A tactic that manipulates people into granting access or revealing sensitive information.
  • zero-trust: A security approach that assumes no user or system should be trusted by default.
  • validator nodes: Systems that help authorize and sign transactions in a bridge or network setup.