BTC $64,942.05 -1.58%
ETH $1,894.34 -2.51%
BNB $566.92 -0.92%
XRP $1.11 -3.29%
SOL $76.33 -2.67%
TRX $0.3264 -0.58%
DOGE $0.0697 -4.63%
ADA $0.1702 -4.91%
BCH $213.98 -3.28%
LINK $8.49 -2.35%
HYPE $59.49 +2.38%
AAVE $95.80 -2.21%
SUI $0.7466 -3.10%
XLM $0.1826 -4.20%
ZEC $514.38 +0.42%
BTC $64,942.05 -1.58%
ETH $1,894.34 -2.51%
BNB $566.92 -0.92%
XRP $1.11 -3.29%
SOL $76.33 -2.67%
TRX $0.3264 -0.58%
DOGE $0.0697 -4.63%
ADA $0.1702 -4.91%
BCH $213.98 -3.28%
LINK $8.49 -2.35%
HYPE $59.49 +2.38%
AAVE $95.80 -2.21%
SUI $0.7466 -3.10%
XLM $0.1826 -4.20%
ZEC $514.38 +0.42%

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

Core Viewpoint
Summary: A year and a half ago, Phemex was also hacked for over 70 million dollars.
ChainCatcher Selection
2026-07-23 21:19:42
Collection
A year and a half ago, Phemex was also hacked for over 70 million dollars.

Author: Gu Yu, ChainCatcher

Today, the cross-chain bridge of the decentralized perpetual contract exchange AFX was attacked by hackers, resulting in over $24 million in assets being stolen. According to the TVL displayed by Defillama, this amount is equivalent to the entire protocol being emptied.

After the incident, AFX posted on X stating that it is working closely with leading security firms, ecosystem partners, exchanges, and relevant authorities to monitor the flow of funds and support the ongoing investigation.

I. Audit Report Full of Holes

However, AFX's painful lesson seems to have had early warning signs. The project officially launched its mainnet in May and released its audit report on June 3. After today's theft incident, several professional security experts found significant issues with this report.

In the report, the security audit firm Zellic stated that it discovered 11 issues, of which two were critical and six were of moderate impact.

"Given that this audit only covered a portion of the components that make up the bridge protocol and lacked testing coverage of all security-critical paths, this is particularly important. This not only limits our ability to verify correctness but also restricts AFX's future capability to maintain a secure system. Additionally, a key factor that urgently needs re-auditing is that we did not have the capability to run or interact in a real-time or local environment at that time. This greatly limited our ability to verify functionality, explore edge cases, and assess system behavior beyond static reviews," Zellic wrote in the summary section.

Image

According to Zellic's disclosure, the code it was able to access and verify only covered part of the bridge protocol components and could not cover the complete asset cross-chain process, nor could it be tested in a real operating environment. This means that for the most critical paths of asset custody, signature verification, and permission control in the cross-chain bridge, the auditing agency could not provide a complete conclusion.

Zellic also specifically warned that even if the project team completed vulnerability fixes based on the report, the auditing agency could not confirm whether these fixes were correctly implemented, nor could it guarantee that new vulnerabilities would not be introduced during the fixing process. This means that the report cannot actually serve as proof that the bridge protocol is "secure," but rather resembles a phase check result for part of the code.

For a cross-chain bridge managing tens of millions of dollars in assets, "incomplete audit scope" itself is a risk. When the auditing agency cannot confirm the security boundaries of the entire system, users also find it difficult to judge the actual security of the protocol.

In response, Taylor Monahan, Chief Product Manager of MetaMask and founder of MyEtherWallet and MyCrypto, tweeted that the AFX cross-chain bridge audit report is "terrifying," with numerous "confirmed" issues left unaddressed, expressing extreme disbelief that users would transfer over $24 million into the protocol.

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

"This audit strongly points to a team that fundamentally does not care about being responsible for a 'not completely true M of N system.' Unhandled edge cases? No problem. Manually operating user funds? No problem. Completely relying on team intervention to prevent being robbed? No problem."

Taylor Monahan speculated that AFX is very likely to have all validators and keys on the same system or controlled by a single individual.

II. Parent Company Suspected to be Phemex

ChainCatcher reporters further researched the AFX team and found that the project seems to have close ties with the cryptocurrency exchange Phemex, and Phemex is likely its parent company.

The intricate connections among team members are one piece of supporting evidence. AFX's growth director Ken's X account previously described him as "Head of Listing @phemex_official," which is a core functional position at any exchange.

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

Another team member followed by AFX's official X account, Damon, although there is no more public information about him, created his X account four months ago and followed at least three team members from Phemex.

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

Additionally, Phemex's official blog has published several articles promoting AFX, such as "Unlock Your Strength: Discover Why AFX Protocol Transforms Lives," "The Philosophy of Anti-Fragility: Why AFX Protocol Matters," "Dive into the Multi-Asset Perps Revolution!," and "Top 5 Perpetual DEXs to Watch in 2026," where AFX was even listed ahead of other Perp DEXs like Hyperliquid.

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

Currently, the aforementioned articles have been deleted from the Phemex official website, but links to these articles still appear in search results when searching for their titles on Google.

Another piece of related evidence is that the logos of the two projects have very similar thematic styles, both using a gradient color scheme from fluorescent green to teal against a pure black background, with nearly identical visual atmosphere and tonal orientation, which may also reflect that they share the same design team.

AFX's bizarre theft case: the audit report is riddled with flaws, and the company behind it is suspected to be the cryptocurrency exchange Phemex

Considering the team's background, official historical promotions, brand design, and public operational traces, there is a connection between AFX and Phemex that far exceeds that of ordinary ecosystem partners.

The most "chilling" question is that Phemex was also hacked for over $70 million in January 2025, which external analysts speculated was likely the work of North Korean hackers. At that time, the Phemex team stated that user assets would not be affected, the platform would bear the losses caused by the incident, and normal withdrawal processes were quickly restored.

During the launch of the AFX product, Phemex clearly prepared for risk isolation in advance, with no public connections between the two on branding, stocks, and other levels, yet the intricate relationship between them cannot be concealed.

Now, the tragedy of losing tens of millions of dollars has replayed. Whether this is a repeat of North Korean hackers' tactics or an insider's scheme to harvest remains to be seen, relying on more evidence and analysis.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.