A Detailed Post-Mortem on the AFX Security Incident

2026-07-31 AFXTrade

https://medium.com/@AFXTrade/a-detailed-post-mortem-on-the-afx-security-incident-57d564ef812f

Thumbnail for A Detailed Post-Mortem on the AFX Security Incident

AFX attributes its July 2026 custody-bridge theft to UNC4899 / TraderTraitor after a developer cloned a malicious DEX repository offered through a fake job approach. A modified Git post-checkout hook launched the initial payload, and the attacker later persisted in AFX's JFrog environment through a malicious Groovy plugin, a trojanized gssproxy binary, and an injected shared library. Credentials recovered from internal files allowed the attacker to abuse an operations bastion and execute a downloader from 23.27.48.177 on DEX validators, which then co-signed the unauthorized bridge transaction. AFX found no evidence that the Arbitrum network or native Arbitrum bridge was compromised.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://git.oddium.io/dex/dex-a… 2026-07-31 2026-07-31
DOMAIN git.oddium.io 2026-07-31 2026-07-31
URL https://23.27.48.177/claude-las… 2026-07-25 2026-07-31
IPv4 23.27.48.177 2026-07-25 2026-07-31

Related Actors

Related Reports

« Back