AFX’s Goodwill Compensation Plan
AFX, a decentralized derivatives platform, is in the process of formulating a goodwill compensation plan for users impacted by a significant security breach that occurred on July 22, leading to a theft of approximately $24.15 million in USDC. The particulars of this recovery proposal are intended for public release on August 3, as confirmed in a recent AFX announcement.
Details of the Security Breach
The breach, which involved the AFX-operated custody bridge, has deeply affected not only its investors but also employees and early supporters. The AFX team has requested patience from its community as they finalize details to address the fallout from this incident.
An internal investigation has clarified that the breach was not due to vulnerabilities within the Arbitrum network’s native bridge but was linked to AFX’s own infrastructure. Blockchain security firm Blockaid, along with the Arbitrum team, verified that the attack stemmed from a social engineering scheme targeted at one of AFX’s developers. It was reported that on July 9, the attacker masqueraded as a recruiter for Oddium Lab to trick the developer into cloning a compromised software repository.
Technical Analysis of the Attack
The malicious repository employed a backdoor capable of executing hidden commands during standard Git processes, which allowed the hacker to gain initial access to the developer’s workstation. With this foothold, the attacker progressed to infiltrate AFX’s internal systems, ultimately leading to the download of critical project source code.
The protocol’s post-incident analysis revealed that the assailant subsequently uploaded a dangerous Groovy plugin to AFX’s JFrog artifact repository, gaining remote code execution. Despite operational issues initially suspected to be routine server problems, the malicious plugin evaded detection and remained active through multiple server restarts. Further investigations indicated that the attacker manipulated system binaries and attempted to erase security logs, contributing to the severity of the breach.
The attack gained momentum as the compromised validator nodes, which had their trust relationships exploited, co-signed a transaction that led to the transfer of $24.15 million in USDC just after 9:27 p.m. UTC on the date of the breach.
AFX has assured that its investigation found no evidence of a compromise within the Arbitrum network, aligning with previous reports from Blockaid and Offchain Labs.
Aftermath and Recovery Efforts
In the aftermath of the exploit, the stolen USDC was tracked across the blockchain. The resources were moved from Arbitrum to Ethereum, where they were exchanged for about 12,467 ETH; however, there has yet to be a report of recovery for any of the stolen assets.
The AFX incident highlights the vulnerabilities present in software supply chains, illustrating that even without direct smart contract exploitation, security can be jeopardized through trusted internal systems. In response to this breach, AFX has undertaken extensive measures, including rebuilding the compromised systems, revamping operational credentials, and improving overall monitoring capabilities. In addition, the protocol plans to enhance their security measures by implementing mandatory reviews and behavioral monitoring alongside training initiatives to combat social engineering threats.
Connection to Known Threat Groups
Additionally, forensic findings suggest a connection between this incident and a known DPRK-associated group, UNC4899, also known as TraderTraitor, which has drawn the attention of security agencies like the FBI and CISA. AFX is continuously coordinating with external security experts to pursue the stolen funds and bolster their defenses moving forward.
Broader Implications
The news from AFX follows a string of recent incidents involving breaches that leveraged compromised support infrastructure rather than exploiting direct vulnerabilities in smart contracts. For example, a separate incident reported by Ostium highlighted unauthorized access to off-chain systems, costing them $23.75 million in USDC, while stablecoin payment firm Triple-A disclosed a breach where unauthorized access to treasury wallets did not affect customer assets or operations.
As AFX prepares to release its recovery plan, the implications of such breaches underscore the critical need for stringent security protocols in the blockchain space.