AFX Trade pledges ‘goodwill plan’ on August 3 after $24M bridge theft

- AFX Trade will unveil a “goodwill plan” on August 3 for users affected by its $24 million bridge breach.
- The attack traced back to a fake job offer that lured a developer into planting malware.
- The hack fits a growing trend of fewer but larger infrastructure-related exploits in 2026.
AFX Trade has informed its community on Friday, July 31, that it will be publishing a “goodwill plan” for users on Monday, August 3.
It may come as a step in the direction of making affected users whole; however, the update stopped short of providing information on what users should be expecting. The message called for calm while the team finalizes a way forward.
It is coming nine days after the platform lost over $24 million due to a breach in its exchange custody bridge.
What did AFX Trade share in its update?
The update was short and it did not provide specifics. The message was shared from AFX Trade’s X account and read, “A goodwill plan is currently in process following the recent security incident, and will be unveiled on Monday August 3rd.”
The team added that investors, staff, and early backers had all been hit by the breach and shared a link to a Medium article that contained a detailed post-mortem.
However, no figures, eligibility rules, or timeline for any payout was shared, and it was not disclosed if that will be shared on the coming Monday as well.
Where did the stolen $24 million go?
The theft occurred on July 22, with security firm Blockaid putting the loss at $24.15 million. The funds were drained from a USDC custody bridge that AFX operates on Arbitrum.
Onchain analysts at PeckShieldAlert stated that the attacker moved the stablecoins to Ethereum and converted them into 12,468 ETH, which came to rest in a single wallet.
AFX Trade paused its bridge operations after it detected the breach and stated that the exploit was limited to the affected bridge. Arbitrum also made a similar statement with cofounder Steven Goldfeder, stating that the network’s native bridge “has not been hacked or exploited in any way” and that the offending transaction came from a third-party protocol sitting on top of the layer-2.
AFX Trade head of growth Ken C made an offer to the attacker, stating that they are willing to allow them to keep 30% of the funds as a white hat bounty if they return 70%.
How was the attacker able to break into AFX Trade USDC Custody bridge?
The detailed post-mortem published by AFX Trade traces the intrusion back to July 9, when a developer was approached over Telegram by someone claiming to represent a firm called Oddium Lab and pitching part-time work.
The developer was steered into cloning what looked like an ordinary DEX aggregator repository. Its .git/config had been altered to fire a malicious post-checkout hook the moment the developer switched branches, planting a first-stage payload on the workstation.
From there, the attacker worked inward rather than on-chain. On July 16, they loaded a rogue Groovy plugin, ops_maintenance.groovy, into AFX Trade’s JFrog artifact repository, which handed them code execution on that host.
The plugin also triggered severe out-of-memory failures that read as an ordinary infrastructure problem, so engineers looped in JFrog’s own support team and restarted the machine, which quietly reloaded the malware.
By July 22, the intruders had reached validator infrastructure, pushed a payload to targeted nodes, and used the compromised validators to co-sign the bridge call that moved the assets out. “It did not exploit a smart contract. It exploited trust,” AFX wrote.
A big single loss in a year of many small ones
The AFX theft fits a pattern that has been occurring all year. TRM Labs reported that attackers pulled off 207 separate hacks in the first half of 2026, the most it has ever recorded in a six-month stretch.

However, total losses fell to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational compromises made up only about 15% of incidents but accounted for around 76% of the money lost.
AFX sits on that heavy end. A separate tally listed AFX’s $24.15 million alongside larger access-control failures such as Kelp DAO’s $292 million and Drift Protocol’s $280 million. DeFiLlama’s exploit database classifies the AFX bridge hit as an infrastructure incident tied to a private key compromise, the same bucket that has driven most of 2026’s dollar losses even as raw exploit counts climb elsewhere.
The smartest crypto minds already read our newsletter. Want in? Join them.
FAQs
How much was stolen from AFX Trade?
Security firm Blockaid put the loss at $24.15 million in USDC, drained from a custody bridge AFX operates on Arbitrum; PeckShield tracked the funds as they were bridged to Ethereum and swapped for 12,468 ETH.
Was the Arbitrum network itself hacked?
No. Arbitrum co-founder Steven Goldfeder said the network's native bridge "has not been hacked or exploited in any way," and AFX said the damage was isolated to the third-party custody bridge it operates.
How did the attackers get in?
According to AFX's post-mortem, the intrusion started on July 9 when a developer was contacted over Telegram and induced to clone a malicious repository, after which the attacker moved through AFX's JFrog build system and eventually compromised validator nodes to sign off the bridge transfer.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















