AFX Trade has informed its community on Friday, July 31, that it will be publishing a “goodwill plan” for users on Monday, August 3. It may come as a step in the direction of making affected
AFX Trade has informed its community on Friday, July 31, that it will be publishing a “goodwill plan” for users on Monday, August 3.
It may come as a step in the direction of making affected users whole; however, the update stopped short of providing information on what users should be expecting. The message called for calm while the team finalizes a way forward.
It is coming nine days after the platform lost over $24 million due to a breach in its exchange custody bridge.
What did AFX Trade share in its update?
The update was short and it did not provide specifics. The message was shared from AFX Trade’s X account and read, “A goodwill plan is currently in process following the recent security incident, and will be unveiled on Monday August 3rd.”
The team added that investors, staff, and early backers had all been hit by the breach and shared a link to a Medium article that contained a detailed post-mortem.
However, no figures, eligibility rules, or timeline for any payout was shared, and it was not disclosed if that will be shared on the coming Monday as well.
Where did the stolen $24 million go?
The theft occurred on July 22, with security firm Blockaid putting the loss at $24.15 million. The funds were drained from a USDC custody bridge that AFX operates on Arbitrum.
Onchain analysts at PeckShieldAlert stated that the attacker moved the stablecoins to Ethereum and converted them into 12,468 ETH, which came to rest in a single wallet.
AFX Trade paused its bridge operations after it detected the breach and stated that the exploit was limited to the affected bridge. Arbitrum also made a similar statement with cofounder Steven Goldfeder, stating that the network’s native bridge “has not been hacked or exploited in any way” and that the offending transaction came from a third-party protocol sitting on top of the layer-2.
AFX Trade head of growth Ken C made an offer to the attacker, stating that they are willing to allow them to keep 30% of the funds as a white hat bounty if they return 70%.
How was the attacker able to break into AFX Trade USDC Custody bridge?
The detailed post-mortem published by AFX Trade traces the intrusion back to July 9, when a developer was approached over Telegram by someone claiming to represent a firm called Oddium Lab and pitching part-time work.
The developer was steered into cloning what looked like an ordinary DEX aggregator repository. Its .git/config had been altered to fire a malicious post-checkout hook the moment the developer switched branches, planting a first-stage payload on the workstation.
From there, the attacker worked inward rather than on-chain. On July 16, they loaded a rogue Groovy plugin, ops_maintenance.groovy, into AFX Trade’s JFrog artifact repository, which handed them code execution on that host.
The plugin also triggered severe out-of-memory failures that read as an ordinary infrastructure problem, so engineers looped in JFrog’s own support team and restarted the machine, which quietly reloaded the malware.
By July 22, the intruders had reached validator infrastructure, pushed a payload to targeted nodes, and used the compromised validators to co-sign the bridge call that moved the assets out. “It did not exploit a smart contract. It exploited trust,” AFX wrote.
A big single loss in a year of many small ones
The AFX theft fits a pattern that has been occurring all year. TRM Labs reported that attackers pulled off 207 separate hacks in the first half of 2026, the most it has ever recorded in a six-month stretch.

Crypto losses by the quarter. Source: TRM Labs.
However, total losses fell to $972 million, less than half of the $2.3 billion stolen a year earlier. Infrastructure and operational compromises made up only about 15% of incidents but accounted for around 76% of the money lost.
AFX sits on that heavy end. A separate tally listed AFX’s $24.15 million alongside larger access-control failures such as Kelp DAO’s $292 million and Drift Protocol’s $280 million. DeFiLlama’s exploit database classifies the AFX bridge hit as an infrastructure incident tied to a private key compromise, the same bucket that has driven most of 2026’s dollar losses even as raw exploit counts climb elsewhere.
The smartest crypto minds already read our newsletter. Want in? Join them.