00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

AFX to Unveil Recovery Plan Following $24.15 Million Social Engineering Hack

A social engineering campaign targeting a single developer’s workstation allowed attackers to siphon $24.15 million from the AFX bridge, prompting the decentralized protocol to schedule a goodwill recovery plan for Aug. 3. The breach bypassed smart contract security by compromising internal validator nodes through trusted management software.

AFX to Unveil Recovery Plan Following $24.15 Million Social Engineering Hack

The attack, which occurred on July 22, began when an operative posing as a recruiter from Oddium Lab tricked an AFX developer into cloning a malicious software repository. This payload granted the attacker remote code execution capabilities, allowing them to pivot from a workstation into the protocol’s internal Ansible-based management infrastructure. By leveraging existing trust relationships, the threat actor deployed code to validator nodes, which then authorized the fraudulent transfer of 24.15 million USDC.

Forensic analysis suggests the breach was the work of UNC4899, a threat group linked to the DPRK, also known as TraderTraitor. While the stolen funds were moved to Ethereum and converted into 12,467 ETH, AFX confirmed that the Arbitrum network itself remained secure throughout the incident. The protocol has since rebuilt its infrastructure, implemented zero-trust segmentation, and rotated all operational credentials to prevent further unauthorized access. The upcoming goodwill plan aims to address losses for investors, employees, and early supporters affected by the theft.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!