AFX said it will publish a goodwill plan on Aug. 3 for users affected by last week’s $24.15 million bridge exploit, as the protocol outlines what it says was a supply-chain attack that led to the loss of funds from its custody bridge.
Recovery proposal due Aug. 3
According to AFX, the upcoming proposal is intended for users impacted by the incident. The protocol has not yet released the details of that plan, but said it has already been prepared and is scheduled to be shared on Aug. 3.
The announcement follows the bridge exploit disclosed last week, in which about $24.15 million in USDC was drained. AFX described the forthcoming plan as a goodwill measure rather than a finalized technical remedy, while continuing its broader response to the breach.
How the breach unfolded
In its post-mortem, AFX said the exploit stemmed from a supply-chain attack that began with social engineering against a developer. The protocol said the compromise spread from there into internal development and validator infrastructure.
AFX said the attacker then moved laterally through its systems before validators ultimately co-signed a bridge transaction. That transaction, according to the protocol, enabled the withdrawal of roughly $24.15 million USDC from the custody bridge.
The project said the incident was limited in scope to the affected bridge systems. It stated that Arbitrum’s native bridge was not compromised and that the Arbitrum network itself was also unaffected.
Containment and infrastructure changes
Following the exploit, AFX said it rebuilt the infrastructure that had been affected, rotated operational credentials, and increased monitoring across its environment. It also said production systems have been migrated into a more isolated setup based on zero-trust principles.
The protocol presented those steps as part of its containment and remediation work after the intrusion. It added that further security reviews will be carried out before production restarts.
AFX also said its next priorities include stronger monitoring, additional threat-hunting exercises, and more employee training designed to reduce the risk of social-engineering attacks.
Attribution and next steps
The investigation has linked the incident to UNC4899, also known as TraderTraitor, which AFX identified as a DPRK-linked threat group. The protocol said it is continuing to work with external security partners as it attempts to trace the stolen assets.
For now, the main immediate milestone is the Aug. 3 release of the user goodwill plan. That proposal is expected to clarify how AFX intends to address losses from the exploit, while the protocol continues its security overhaul and forensic investigation. The company’s account so far leaves the technical chain of events tied to a compromised internal environment rather than any breach of Arbitrum itself.
Source: crypto.news