In a rare twist for DeFi exploits, the $24.15 million theft from AFX’s bridge wasn’t caused by buggy code but by a carefully executed social engineering scheme. Instead of exploiting smart contract vulnerabilities, hackers linked to North Korea deployed a fake recruiter tactic that snared one of AFX's developers, opening the door to a major $24 million USDC breach.

Social Engineering, Not Code Exploits, Drove the Attack

The attack began on July 9. Hackers posing as a recruiter from Oddium Lab contacted an AFX developer with a bogus job offer. This false recruitment effort gave the attackers access to AFX-managed infrastructure, bypassing technical defenses that protect the Arbitrum network and its native bridge. By July 22, the protocol had lost $24.15 million in USDC, subsequently converted into around 12,467 ETH. This method highlights a shift in tactics where cybercriminals focus on human vulnerabilities rather than the blockchain software itself.

AFX Reels and Prepares Recovery Plan Amidst Uncertainty

Almost a week after the breach became public, AFX confirmed they are assembling a goodwill recovery plan. Set to launch on August 3, the plan aims to support affected users, including investors and early backers. However, goodwill plans often signal partial compensation at best; full restitution remains unlikely. The hack shook community confidence since no funds have been reported as returned and the attacker declined an earlier white-hat bounty offer that would have allowed them to keep 30% if 70% was returned.

Forensic firms and US agencies, including Mandiant, Microsoft Threat Intelligence, the FBI, and CISA, have linked the incident to UNC4899 or TraderTraitor, a North Korean-backed hacking group known for supply chain assaults on cryptocurrency targets. This episode adds to the growing catalog of high-profile attacks involving nation-state actors exploiting social vectors.