Refreshed 5h ago· updates every 6h

AFX Trade (2026) — Crypto Hack

Active
Jul 22, 2026·
Arbitrum
Amount Stolen
$24.1M
~$24.15M
Recovered
$0

Arbitrum-based perpetual DEX AFX Trade was drained of ~$24.15M after bridge validator signing keys were compromised via social engineering. A fake recruiter sent a malicious Git repo to a developer, then pivoted to validator nodes. 5 of 7 validators were compromised. Attributed to UNC4899/TraderTraitor (DPRK).

Summary

Arbitrum-based perpetual DEX AFX Trade was drained of ~$24.15M after bridge validator signing keys were compromised via social engineering. A fake recruiter sent a malicious Git repo to a developer, then pivoted to validator nodes. 5 of 7 validators were compromised. Attributed to UNC4899/TraderTraitor (DPRK).

How It Was Compromised — Bridge via Social Engineering / Validator Key Compromise

BridgeSocial Engineering / Validator Key Compromise

AFX Trade, an Arbitrum-based perpetual DEX, was drained of approximately $24.15 million on July 22, 2026, after bridge validator signing keys were compromised through a sophisticated social engineering campaign. The attack began on July 9 when an attacker posing as a recruiter from a fake company called Oddium Lab sent a malicious Git repository to a developer. The attacker then pivoted from the compromised developer machine to validator nodes via Ansible automation tooling. Five of seven validators were compromised, giving the attacker sufficient signing power to authorize fraudulent bridge transactions. The attack was attributed to UNC4899, also known as TraderTraitor, a North Korean (DPRK) state-sponsored threat actor group.

Fund Flow & Laundering Analysis

Stolen funds were bridged from Arbitrum and laundered through multiple decentralized exchanges and cross-chain bridges, consistent with DPRK TraderTraitor laundering patterns.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.