๐Ÿ“… Monday, 7 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Korea Utara Gasak $24 Juta Lewat Lowongan Kerja Bodong - AFX Jadwalkan Ganti Rugi Senin Besok

North Korean Hackers Steal $24M via Fake Job Scam - AFX Schedules Compensation Plan for Monday

Decentralized derivatives protocol AFX lost 24.15 million USDC on July 22, 2026, at 21:27 UTC. Rather than exploiting a smart contract, the attacker posed as a job recruiter to deceive a developer and breach internal infrastructure.

Now, the protocol must devise a compensation plan to cover user losses.

Starting with a Fake Job Offer

The attacker approached an AFX software developer on July 9, 2026. Posing as a recruiter from an entity named “Oddium Lab”, they persuaded the victim to clone a seemingly legitimate code repository. Behind the scenes, the repository contained a malicious Git configuration that triggered a hidden payload whenever the developer ran routine workflows.

The attacker leveraged this initial access to upload a compromised Groovy plugin to AFX’s JFrog artifact repository. From there, they gained remote code execution access to an Ansible-based internal management system. Because this system had privileged access to validator nodes, the hackers moved freely across the production infrastructure. Ultimately, infected validators co-signed cross-chain bridge transactions that transferred 24.15 million USDC out of the AFX ecosystem. The stolen funds were then bridged from Arbitrum to Ethereum and swapped for approximately 12,467 ETH.

Who Is Behind the Attack?

Based on forensic analysis, AFX concluded that the attack tactics match the modus operandi of UNC4899 or TraderTraitor. This hacking group is affiliated with the North Korean government and has been closely tracked by Mandiant, Microsoft, the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA). The incident demonstrates that software supply chain attacks can drain crypto assets without compromising the underlying security of the blockchain.

In response to the breach, AFX scheduled the release of a compensation document or “goodwill plan” for affected users on Monday, August 3, 2026. AFX also emphasized that Arbitrum’s main network and native bridge remain secure. The exploit was confined entirely to custom storage bridges and infrastructure operated by AFX. This was corroborated by Steven Goldfeder, co-founder of Offchain Labs, who confirmed that the suspicious transactions originated from a third-party protocol and not Arbitrum’s core bridge.

Following the hack, AFX claimed to have rebuilt its entire infrastructure, rotated all credentials, tightened monitoring, and transitioned to a zero-trust network architecture. For the broader crypto industry, however, the breach via a fraudulent job offer serves as a stark reminder. No matter how advanced cryptographic security is at the network level, millions of dollars can vanish simply due to a single employee’s oversight when replying to an online message.

Reported by crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share