AFX Bridge Incident: What Happened, What We Learned, and What Comes Next

2026-07-25 AFXTrade

https://medium.com/@AFXTrade/afx-bridge-incident-what-happened-what-we-learned-and-what-comes-next-d97387746012

Thumbnail for AFX Bridge Incident: What Happened, What We Learned, and What Comes Next

An attacker stole assets from AFX's custody bridge after compromising a developer through a malicious repository shared over Telegram. The intrusion spread into AFX's JFrog environment, where a malicious Groovy plugin and modified system components maintained persistence before the attacker moved laterally to validator-related infrastructure. A remote payload downloaded from 23.27.48.177 ultimately enabled unauthorized bridge access. AFX found no evidence that the Arbitrum network or native Arbitrum bridge was compromised.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://23.27.48.177/claude-las… 2026-07-25 2026-07-31
IPv4 23.27.48.177 2026-07-25 2026-07-31

Related Reports

« Back