A Detailed Post-Mortem on the AFX Security Incident
2026-07-31 • AFXTrade •
https://medium.com/@AFXTrade/a-detailed-post-mortem-on-the-afx-security-incident-57d564ef812f
AFX attributes its July 2026 custody-bridge theft to UNC4899 / TraderTraitor after a developer cloned a malicious DEX repository offered through a fake job approach. A modified Git post-checkout hook launched the initial payload, and the attacker later persisted in AFX's JFrog environment through a malicious Groovy plugin, a trojanized gssproxy binary, and an injected shared library. Credentials recovered from internal files allowed the attacker to abuse an operations bastion and execute a downloader from 23.27.48.177 on DEX validators, which then co-signed the unauthorized bridge transaction. AFX found no evidence that the Arbitrum network or native Arbitrum bridge was compromised.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://git.oddium.io/dex/dex-a… | 2026-07-31 | 2026-07-31 |
| DOMAIN | git.oddium.io | 2026-07-31 | 2026-07-31 |
| URL | https://23.27.48.177/claude-las… | 2026-07-25 | 2026-07-31 |
| IPv4 | 23.27.48.177 | 2026-07-25 | 2026-07-31 |