
AFX has announced that it has prepared a goodwill plan for users affected by last week’s $24.15 million bridge exploit, with the recovery proposal scheduled for release on Aug. 3.
Summary
- AFX will announce a goodwill plan for users affected by its $24.15 million bridge exploit on Aug. 3.
- The protocol said its investigation found the attack began with a social engineering campaign that compromised internal development infrastructure.
- AFX said the exploit targeted its own custody bridge and did not affect Arbitrum’s native bridge.
- The protocol has rebuilt key infrastructure and introduced additional security measures while recovery efforts continue.
According to an announcement shared by AFX, the decentralized derivatives protocol is finalizing a goodwill plan following the July 22 security incident and will publish the details on Monday, Aug. 3. The team said investors, employees and early supporters had all been affected by the attack and asked the community to remain patient while it completes the final proposal.
The update comes after AFX completed its technical investigation into the exploit, which resulted in the theft of about 24.15 million USDC from an AFX-operated custody bridge. The protocol has not yet disclosed how compensation or recovery will be structured, but said its next announcement will focus on the goodwill plan.
Earlier public statements confirmed the exploit targeted infrastructure operated by AFX rather than Arbitrum’s native bridge. At the time, blockchain security firm Blockaid and the Arbitrum team investigated the incident, while Offchain Labs co-founder Steven Goldfeder said the suspicious transaction originated from a third-party protocol instead of Arbitrum’s core bridge.
AFX says attack started with a developer
In a detailed post-mortem released after the incident, AFX said the breach originated from a social engineering campaign against one of its developers rather than a vulnerability in its smart contracts or blockchain infrastructure. According to the protocol, the attacker posed as a recruiter from a company called Oddium Lab on July 9 and convinced the developer to clone what appeared to be a legitimate software repository.
AFX said the repository contained a malicious Git configuration that executed a hidden payload during a routine Git workflow, giving the attacker an initial foothold inside the developer’s workstation. Using the compromised device, the attacker gradually expanded access across internal development systems before downloading project source code several days later.
The investigation said the attacker later uploaded a malicious Groovy plugin into the protocol’s JFrog artifact repository, obtaining remote code execution inside the software delivery environment. According to AFX, repeated out-of-memory events on the JFrog server were initially treated as operational problems with assistance from the vendor, allowing the malicious plugin to survive multiple restarts without triggering a security response.
Forensic analysis later found that the attacker had replaced system binaries with trojanized versions, injected malicious shared libraries and attempted to erase security logs before portions of the malware crashed. SELinux logs captured outbound command-and-control traffic, shell execution and in-memory code execution that became important evidence during the investigation, according to the report.
Validator compromise enabled the bridge theft
The protocol said the attacker eventually pivoted from the compromised development environment into its operational infrastructure using an internal Ansible-based management service that already held privileged access to validator nodes. Rather than stealing new credentials or exploiting an external service, the attacker used existing trust relationships to deploy malicious payloads across a subset of validators.
AFX said the infected validator nodes downloaded a second-stage payload from a remote server before interfering with consensus-message handling. At 9:27 p.m. UTC on July 22, the affected validators co-signed a bridge transaction that transferred roughly 24.15 million USDC from the AFX-operated custody bridge.
The protocol said its investigation found no evidence that the Arbitrum network or Arbitrum’s native bridge had been compromised. The attack remained confined to infrastructure managed by AFX, matching statements previously issued by Offchain Labs and Blockaid during the initial response.
On-chain investigators later tracked the stolen USDC after it moved from Arbitrum to Ethereum, where the proceeds were converted into approximately 12,467 ETH. At the time of the initial investigation, no public reports confirmed that any portion of the stolen assets had been recovered.
Investigation points to supply chain compromise
According to AFX, the incident demonstrated that software supply chain attacks can bypass blockchain security without exploiting smart contracts directly. The protocol concluded that the attack relied on trusted development tools, internal deployment systems and validator infrastructure instead of weaknesses in on-chain code.
The report said the protocol has rebuilt affected infrastructure, rotated operational credentials, increased monitoring sensitivity and migrated production systems into a more isolated environment with zero-trust segmentation. Additional work planned over the coming months includes stronger behavioral monitoring, mandatory security reviews before restarting production services, expanded threat-hunting exercises and employee training against social engineering attacks.
Based on forensic evidence, attack techniques and infrastructure observed during the investigation, AFX said its findings are consistent with independent attribution linking the incident to UNC4899, also known as TraderTraitor, a DPRK-linked threat group tracked by Mandiant, Microsoft Threat Intelligence, the FBI and CISA. The protocol said it continues working with external security partners to trace the stolen assets and support ongoing response efforts.
Off-chain attacks have surfaced in multiple DeFi exploits
The latest findings add to a series of incidents in which protocols have concluded that attackers compromised supporting infrastructure instead of exploiting flaws in smart contracts.
On July 30, Ostium said its investigation into a separate 23.75 million USDC exploit found that unauthorized access to off-chain infrastructure allowed fraudulent BTC-USD price reports to drain funds from its liquidity vault, while its smart contracts and governance multisigs remained uncompromised.
Earlier this month, Singapore-based stablecoin payments firm Triple-A also disclosed unauthorized access to treasury wallets holding company-owned digital assets, although it said customer funds and payment operations were unaffected.






