AFX bridge exploit recovery: North Korea stole $24M via fake job offer

NewsFri, 31 Jul 2026 09:00:22 UTC5 hours ago
AFX bridge exploit recovery: North Korea stole $24M via fake job offer

A North Korean-linked hacking group walked away with $24.15 million in USDC from a decentralized derivatives protocol — and the method had nothing to do with faulty smart contracts. The AFX bridge exploit recovery process is now entering a critical public phase, with the protocol set to unveil a goodwill plan for affected users on August 3, following one of the most technically sophisticated supply chain attacks seen in DeFi this year.

Key takeaways

  • AFX will release a goodwill recovery plan for users affected by the exploit on August 3, 2026.
  • About $24.15 million USDC was stolen from AFX’s custody bridge on July 22 and later converted into approximately 12,467 ETH.
  • The attack originated from a social engineering campaign starting July 9, targeting an AFX developer via a fake recruiter posing as Oddium Lab.
  • Arbitrum’s native bridge and network were not compromised; the breach was entirely contained within AFX-managed infrastructure.
  • Forensic evidence links the attack to UNC4899, also known as TraderTraitor, a DPRK-backed threat group tracked by Mandiant, Microsoft Threat Intelligence, the FBI, and CISA.

AFX announces goodwill plan for $24.15 million bridge exploit victims

The announcement, published July 31, confirmed that AFX is finalizing a goodwill plan and will release the full details on Monday, August 3. The team acknowledged that investors, employees, and early supporters had all been affected and asked the community for patience while the proposal is completed. The exact structure of any compensation or recovery mechanism has not yet been disclosed.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related