AFX Suffers $24.15M Bridge Hack After Developer Falls Victim to Social Engineering
A protocol that operates on the Arbitrum blockchain has been targeted by a sophisticated attack. On July 22, an attacker stole approximately $24.15 million from AFX's custody bridge in what is being described as a 'social engineering campaign.' The breach began when an attacker posed as a recruiter for Oddium Lab and convinced one of AFX's developers to clone a software repository that contained malicious code.
The developer was tricked into downloading the malicious Git configuration, which executed a hidden payload during a routine workflow. This gave the attacker an initial foothold inside the developer's workstation, allowing them to expand access across internal development systems before uploading a malicious Groovy plugin into AFX's JFrog artifact repository.
The attackers used existing trust relationships to deploy payloads across a subset of validators and eventually stole $24.15 million from the custody bridge. The protocol said that its investigation found no evidence that the Arbitrum network or native bridge had been compromised, matching earlier statements by Offchain Labs and Blockaid.
AFX has rebuilt affected infrastructure, rotated operational credentials, increased monitoring sensitivity, and migrated production systems into a more isolated environment with zero-trust segmentation. The protocol said it continues working with external security partners to trace the stolen assets and support ongoing response efforts.