Login
Sign Up
Woofun AI reports that the AFX decentralized perpetual contract exchange bridge was compromised, resulting in the theft of assets valued at over $24 million. This incident has triggered immediate scrutiny regarding the protocol’s security infrastructure and its opaque operational ties to the cryptocurrency exchange Phemex. The breach effectively drained the entire protocol, as evidenced by the Total Value Locked (TVL) metrics displayed on Defillama, marking a catastrophic failure for the platform shortly after its mainnet launch. In the immediate aftermath, AFX issued a statement on X, asserting that it is collaborating with leading security companies, ecosystem partners, exchanges, and relevant authorities to monitor fund flows and support the ongoing investigation into the theft.
The financial devastation is absolute, with the $24 million loss representing the complete evacuation of the protocol’s liquidity. The TVL prior to the attack was equivalent to the stolen amount, indicating that no residual funds remained for users or operators. This total liquidation underscores the severity of the breach, which went beyond a partial exploit to a comprehensive system failure. The response from AFX highlights a reliance on external entities for recovery, yet the absence of frozen funds or recovered assets suggests a high probability of permanent loss for victims. The involvement of leading security companies and relevant authorities indicates an attempt to trace the illicit transfers, but the speed and completeness of the drain complicate any immediate remediation efforts.
The roots of this vulnerability appear to have been visible well before the attack, particularly in the audit process conducted prior to the mainnet launch in May. On June 3, the project released an audit report prepared by the security firm Zellic, which has since come under heavy criticism from industry experts. The report identified 11 issues in total, including two critical findings—one categorized as having high impact—and six moderate-impact issues. Despite these identified risks, the protocol proceeded to launch, exposing users to a system that had already been flagged for significant deficiencies. The timing of the release, just weeks before the hack, raises questions about the prioritization of security over speed to market, a common but dangerous trend in the decentralized finance sector.
A deeper examination of the audit scope reveals fundamental limitations that likely contributed to the breach. Zellic explicitly stated that the audit covered only some components of the bridge protocol, failing to test all critical security paths. This partial coverage severely restricted the ability to verify the correctness of the entire system and limited AFX’s capacity to maintain robust security standards.
Furthermore, the auditors noted a critical inability to run or interact with the protocol in a real-time or local environment, which confined their analysis to static reviews. This lack of dynamic testing prevented the exploration of edge cases and the assessment of system behavior under actual operating conditions, leaving potential vulnerabilities undetected.
The consequences of these audit limitations were severe, particularly regarding the most sensitive aspects of the bridge’s architecture. Key functions such as asset custody, signature verification, and permission control were not comprehensively assessed due to the incomplete audit scope. Zellic emphasized that even if the project team addressed the identified vulnerabilities, the firm could not confirm the proper implementation of these fixes or guarantee that new vulnerabilities did not arise during the repair process. This uncertainty means that the audit report cannot serve as a definitive proof of security, but rather as a partial inspection of specific code segments. For a cross-chain bridge managing tens of millions of dollars, such gaps in verification constitute an unacceptable risk, leaving users exposed to exploits that static analysis might miss.
Woofun AI data shows that industry experts have voiced strong criticism of the audit’s inadequacies, with Taylor Monahan, Chief Product Manager of MetaMask and founder of MyEtherWallet and MyCrypto, describing the report as "very scary." Monahan highlighted that numerous "confirmed" issues remained unfixed, expressing confusion over why users would transfer over $24 million into a protocol with such known deficiencies. He speculated that the audit indicated a team indifferent to responsibility, particularly in the absence of a true M of N system for key management. Monahan suggested that unaddressed edge cases and the reliance on manual intervention to prevent theft pointed to a highly centralized and fragile security model, where validators and keys might be controlled by a single entity or system, creating a single point of failure.
Investigations into the background of AFX reveal intricate personnel links to Phemex, suggesting a deeper relationship than publicly acknowledged. Ken, identified as AFX’s growth director, previously listed his X profile as "Head of Listing @phemex_official," a role responsible for listing new tokens on the exchange—a position of significant influence and trust. Another team member, Damon, who is followed by AFX’s official X account, has limited public information but was observed following at least three team members from Phemex’s X account just four months after creating his own profile. These connections suggest a shared human capital base, raising questions about the independence of AFX’s operations and the potential for shared security practices or vulnerabilities between the two entities.
Beyond personnel, promotional and branding connections further blur the lines between AFX and Phemex. Phemex’s official blog previously published several articles promoting AFX, including titles such as "Unlock Your Strength: Discover Why AFX Protocol Transforms Lives," "The Philosophy of Anti-Fragility: Why AFX Protocol Matters," "Dive into the Multi-Asset Perps Revolution!," and "Top 5 Perpetual DEXs to Watch in 2026." In the latter article, AFX was ranked ahead of other perpetual DEXs like Hyperliquid, indicating a level of endorsement from Phemex. Although these articles have since been removed from Phemex’s website, their links remain in search results, preserving the historical record of this promotion.
Additionally, the visual branding of both projects is strikingly similar, featuring a gradient from fluorescent green to cyan green on a pure black background, suggesting a shared design team or brand identity strategy.
The context of Phemex’s own security history adds a layer of complexity to the current situation. In January 2025, Phemex suffered a hack that resulted in the loss of over $70 million, with analysts speculating that North Korean hackers were responsible. At the time, Phemex assured users that their assets were safe and that the platform would cover the losses, quickly restoring normal withdrawal processes. During the development of AFX, Phemex appeared to implement risk isolation measures, possibly to shield its main operations from similar threats.
However, the close ties between the two projects, despite no public indication of ownership, suggest that the security failures may be interconnected. The recurrence of a major hack involving tens of millions of dollars raises concerns about whether the same threat actors or internal weaknesses are at play.
As the investigation continues, the question remains whether this incident is the work of external hackers, such as the North Korean groups linked to the Phemex breach, or an internal betrayal facilitated by the close ties between the two organizations. The flawed audit, incomplete security testing, and opaque operational links create a scenario where accountability is difficult to assign. Further evidence and analysis are required to determine the full extent of the compromise and the role of Phemex in the AFX protocol’s security framework. This incident serves as a stark reminder of the risks associated with inadequate auditing and the dangers of assuming security based on superficial endorsements or branding similarities.