AFX Trade Tells Hacker to Keep 30% of the $24M Stolen to Give the Rest Back

Key highlights:

  • AFX Trade proposed an attacker a white hat deal in a bid to recover the funds.
  • $24.15 million in USDC was drained from the protocol by the attacker.
  • The exploit affected the protocol’s bridge, while its trading platform was operational.

Arbitrium-based AFX Trade offered an unusual deal to one of the latest hackers to strike DeFi. The entity stole about $24 million from the protocol. 

In response, the team asked the attacker to keep 30% of the stolen funds and voluntarily return the remaining 70%. The team said its main goal is to recover as much money as they can for its users to reduce the damage caused by the incident.

AFX Trade offers hacker a white hat deal

In a post on X, AFX Trade Head of Growth Ken Xi said the project has offered the attacker a “white hat agreement.” This kind of deal is seldom used after crypto hacks. This allows attackers to keep part of the stolen assets if they cooperate by returning the rest without facing legal action.

“We are extending a white hat settlement offer to the party responsible for the recent bridge incident, Ken said. “Our priority is the recovery of user assets and a swift resolution for the community. We encourage you to act in good faith.”

The team said that the attack only affected the protocol’s bridge solution. Its trading systems and the Arbitrum blockchain were not compromised and are operating normally.

“We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Steven Goldfeder, co-founder of Offchain Labs, confirmed.

Lookonchain data highlighted that the party was able to drain about $24.15 million in USDC after gaining control of validator signing keys used by the bridge. The attacker then moved the funds to Ethereum and swapped them for about 12,467 ETH, worth $24 million. Data shows the funds are currently sitting in a single wallet.

The hacker compromised the private keys that approve withdrawals instead of breaking the smart contract itself.

Security firm Blockaid said the bridge’s on-chain code worked exactly as designed. The issue happened off-chain, where the attacker gained access to the validator keys. Five validator signatures approved the withdrawal. This met the bridge’s required approval count.

Bridge hacks continue to trouble DeFi

This is just the latest of the list of attacks that have happened in July. Experts have said many of these attacks are focusing on off-chain systems because it is easier to exploit than coding mistakes in blockchain applications. 

This attack also comes just as activity is building up on the platform. According to DeFiLlama data, trading activity had been rising in July, with perpetual futures volume reaching multi-month highs. The protocol’s total value locked also increased significantly.

Source: DeFiLlama

Interestingly, another attack happened around the same time AFX Trade was exploited. Blockaid detected a hack on the Verus Ethereum bridge. Here, attackers drained $7.5 million in various crypto assets. Meanwhile, this same platform had already been exploited in May.

There were also other cases. For example, attackers stole about $13 million worth of NIGHT tokens from the Wanchain bridge. The Ostium protocol also suffered losses between $18 million and $22 million after an exploit of its liquidity pool.

Just yesterday, SecondFi said it would shut down operations after hackers stole $2.6 million from user wallets following a cryptographic loophole. These attacks show that security is still a major challenge in decentralized finance.

Source:: AFX Trade Tells Hacker to Keep 30% of the $24M Stolen to Give the Rest Back