AFX Bridge Incident: What Happened, What We Learned, and What Comes Next
2026-07-25 • AFXTrade •
An attacker stole assets from AFX's custody bridge after compromising a developer through a malicious repository shared over Telegram. The intrusion spread into AFX's JFrog environment, where a malicious Groovy plugin and modified system components maintained persistence before the attacker moved laterally to validator-related infrastructure. A remote payload downloaded from 23.27.48.177 ultimately enabled unauthorized bridge access. AFX found no evidence that the Arbitrum network or native Arbitrum bridge was compromised.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://23.27.48.177/claude-las… | 2026-07-25 | 2026-07-31 |
| IPv4 | 23.27.48.177 | 2026-07-25 | 2026-07-31 |
Related Reports
Shares tag: DeFi • Published within a month
2026-06-17 •
30% Match
#Cryptocurrency
#Phishing
#DeFi
#FinancialGain
#T1552
#T1078
#T1098
#HumanityProto
Shares tag: DeFi
Shares tag: DeFi
2026-04-21 •
25% Match
#Cryptocurrency
#Whitepaper
#DeFi
#MoneyLaundering
#Bybit
#SafeWallet
#DriftProtocol
#KelpDAO
#T1090
#T1027
#T1566
#T1195
#T1583
#T1584
Shares tag: DeFi
Shares tag: DeFi
Shares tag: DeFi