$24 Million USDC Heist: North Korean-Linked Group Behind Decentralized Derivatives Protocol Hack
A North Korean-linked hacking group has been linked to a $24 million heist from AFX's custody bridge, a decentralized derivatives protocol. The attack, which occurred on July 22, saw approximately $24.15 million in USDC stolen and converted into around 12,467 ETH.
The attacker posed as a recruiter from a company called Oddium Lab and convinced an AFX developer to clone what appeared to be a legitimate software repository. The malicious code was hidden inside the cloned repository and executed a payload during a standard Git workflow, giving the attacker initial access to the developer's workstation.
The intrusion escalated methodically, with the attacker expanding access across internal development systems and uploading a malicious Groovy plugin into AFX's JFrog artifact repository. This allowed them to execute remote code inside the protocol's software delivery environment.