AFX Bridge

#AFX • 2026-07

🇬🇧 United Kingdom

On 22 July 2026, UNC4899 / TraderTraitor compromised AFX's custody bridge after a fake job approach led a developer to clone a malicious repository. The attacker persisted in AFX's JFrog infrastructure, used stolen credentials to abuse an operations bastion, and deployed malware to DEX validators, causing them to co-sign an unauthorized bridge transaction and transfer assets out of AFX custody. AFX said the compromise was confined to its own infrastructure and found no evidence that Arbitrum or the native Arbitrum bridge was breached.

Related Actors

UNC4899

Mandiant

UNC4899 is a designation Mandiant uses for a Democratic People's Republic of Korea-nexus threat actor that Mandiant assesses, with high confidence, functions as a cryptocurrency-focused element within North Korea's Reconnaissance General Bureau, and which Mandiant believes likely corresponds to the actor publicly reported as TraderTraitor. Mandiant first disclosed the designation in connection with a July 2023 supply-chain compromise in which the actor gained initial access to a software solutions company by compromising the JumpCloud identity and access management platform, deploying a malicious Ruby script through JumpCloud's agent to reach downstream customer systems. The intrusion involved macOS backdoors that Mandiant named FULLHOUSE.DOORED and STRATOFEAR, deployed within 24 hours of initial access and disguised as legitimate applications such as Docker and Zoom components. In subsequent reporting, Mandiant grouped UNC4899 with a related cluster, UNC4736, behind the 3CX and Trading Technologies supply-chain attacks, describing both as sophisticated, consistent operations that use trusted software providers to gain broad downstream network access.

North Korea Leverages SaaS Provider in a Targeted…
Associated with: Trader Traitor
First seen: 2023-07 • Last seen: 2026-07

Related Reports

« Back