AFX Trade hack — July 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 23, 2026 |
| Target type | Cross-chain bridge |
| Loss | $24,150,000Price at time of incident |
| Method | Private key compromiseSocial-engineering entry followed by a software supply-chain compromise that ended in validator key control. A developer was induced to clone a malicious repository; the attacker used that foothold to take AFX's source code, then uploaded a malicious Groovy plugin (ops_maintenance.groovy) to AFX's JFrog artifact repository, gaining code execution inside the software delivery pipeline. Persistence was maintained via a modified gssproxy process and injected libraries. The attacker then reached an internal Ansible-based management service that already held privileged access to validator nodes and pushed payloads interfering with consensus-message handling, after which the compromised validators co-signed a fraudulent bridge withdrawal. Blockaid found that five hot-validator signatures authorised the transfer, clearing the roughly two-thirds quorum the bridge required. |
| Chains | Arbitrum, Ethereum |
| Attributed to | UNC4899 / TraderTraitor (DPRK-linked)Suspected |
| Outcome | Unresolved |
What happened
AFX Trade, a perpetuals exchange operating on Arbitrum, lost 24.15 million USDC on 22 July 2026 when attackers gained control of the validator set behind the custody bridge it operates. The bridge is AFX's own infrastructure. Offchain Labs chief executive Steven Goldfeder stated publicly that Arbitrum's native bridge had not been hacked or exploited and that the compromised component belonged to a third-party protocol.
AFX's post-mortem sets out the early intrusion chain. On 9 July a developer was contacted on Telegram by someone posing as a recruiter and was induced to clone a repository from git.oddium.io containing hidden malicious configuration; FinanceFeeds names the fake employer as Oddium Lab. The attacker used that foothold to obtain AFX's source code, and on 16 July uploaded a malicious Groovy plugin, ops_maintenance.groovy, to the company's JFrog artifact repository, gaining code execution inside the software delivery pipeline. Persistence was maintained through a modified gssproxy process and injected libraries. FinanceFeeds reports that the attacker then reached an internal Ansible-based management service that already held privileged access to validator nodes and pushed payloads that interfered with consensus-message handling.
At about 21:27 UTC on 22 July the compromised validators co-signed a withdrawal from the custody bridge. The security firm Blockaid found that five hot-validator signatures authorised the transfer, clearing the roughly two-thirds quorum the bridge required; the contract verified the signatures and executed as designed. The USDC was bridged to Ethereum and swapped for roughly 12,467 ETH, reported by PeckShield as sitting in a single address.
AFX suspended bridge operations and offered the attacker a settlement allowing them to retain 30 percent, about $7.2 million, in exchange for returning the rest. No return was reported. AFX said its forensic findings were consistent with independent attribution of the intrusion to UNC4899, also tracked as TraderTraitor, a North Korea-linked group tracked by Mandiant, Microsoft Threat Intelligence, the FBI and CISA. A recovery plan for affected users was promised for 3 August 2026.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- crypto.newsSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Crypto BriefingSecondary · retrieved 2026-08-01
Official post-mortem: https://crypto.news/afx-schedules-aug-3-goodwill-plan-following-24-15m-bridge-hack/
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "AFX Trade hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/afx-tradehttps://itokenly.com/hacks/afx-tradePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.