AFX, a decentralized perpetual futures exchange, lost more than $24 million after its cross-chain bridge was hacked on Friday. Based on DefiLlama TVL data cited in the report, the stolen amount was effectively large enough to drain the protocol.
After the breach, AFX said in a post on X that it was working closely with leading security companies, ecosystem partners, exchanges and relevant authorities to monitor the movement of funds and support the ongoing investigation.
Zellic audit faces sharp criticism after the hack
AFX launched its mainnet in May and published an audit report on June 3. After the theft, several security professionals said the report itself raised serious concerns.
In that report, security auditor Zellic said it found 11 issues, including two critical findings, one high-severity issue and six medium-severity issues.

Zellic wrote in its conclusion: "Given that this audit covered only a subset of the components that make up the bridge protocol, and lacked testing coverage across all security-critical paths, this is particularly important. This not only limited our ability to verify correctness, but also limited AFX’s future ability to maintain the system securely. In addition, a key factor that urgently warranted a re-audit was that we were not able to run or interact with the system in either a live or local environment at the time. This significantly limited our ability to verify functionality, explore edge cases, and assess system behavior beyond static review."
According to Zellic’s disclosure, the code it could access and verify covered only some bridge components. It did not cover the full cross-chain asset flow and could not be tested in a real operating environment. That left the most sensitive paths in the bridge — asset custody, signature verification and permission controls — outside a complete conclusion.
Zellic also said that even if the project team fixed the issues listed in the report, the auditor could not confirm whether those fixes had been implemented correctly, nor whether new vulnerabilities had been introduced in the process. In practical terms, the report did not amount to proof that the bridge was secure. It was closer to a point-in-time review of only part of the codebase.

For a bridge handling tens of millions of dollars in assets, an incomplete audit scope is a risk by itself. If the auditor cannot define the security boundary of the full system, users have little basis for judging the protocol’s actual safety.
Taylor Monahan, chief product officer at MetaMask and founder of MyEtherWallet and MyCrypto, said on X that the AFX bridge audit was "absolutely terrifying." She said many issues marked as "acknowledged" had not been fixed, and added that she could not understand why users had deposited more than $24 million into the protocol.
Monahan wrote: "This audit strongly points to a team that fundamentally does not care to be responsible for a system that isn’t really M of N. Unhandled edge cases? Fine. Manual handling of user funds? Fine. Total dependence on team intervention to avoid being robbed? Fine."

She also speculated that AFX may have had all validators and keys on the same system, or under the control of a single person.
Public traces point to possible ties with Phemex
ChainCatcher said its review of the AFX team suggested the project had close links to crypto exchange Phemex, and that Phemex may even have been its parent company.
One supporting point came from public team profiles. Ken, AFX’s head of growth, previously described himself on X as "Head of Listing @phemex_official," a role the report described as one of the core functions at any exchange.
Another team-linked account followed by AFX’s official X profile belonged to Damon. While little public information was available about him, the report said his X account was created four months earlier, followed the AFX account, and also followed at least three X accounts belonging to Phemex team members.
There were also traces in Phemex’s own content. The exchange’s official blog had published several promotional articles about AFX, including Unlock Your Strength: Discover Why AFX Protocol Transforms Lives, The Philosophy of Anti-Fragility: Why AFX Protocol Matters, Dive into the Multi-Asset Perps Revolution! and Top 5 Perpetual DEXs to Watch in 2026. In the last article, AFX was placed ahead of other perpetual DEXs such as Hyperliquid.
Those articles have now been removed from the Phemex website. Even so, the report said the links still appear in Google search results when the titles are searched.

Another point raised in the report involved visual identity. AFX and Phemex use closely related logo styles, with fluorescent green-to-teal gradients set against black backgrounds. The overall look and color direction are nearly the same, which the report said could indicate the use of the same design team.
Taking team backgrounds, historical promotion, brand design and operating traces together, ChainCatcher said the relationship between AFX and Phemex appeared to go well beyond that of ordinary ecosystem partners.
Phemex had its own major hack in January 2025
The report also pointed to an earlier incident at Phemex. In January 2025, the exchange lost more than $70 million in a hack. At the time, outside analysis said North Korean hackers were the most likely culprit.

Phemex said then that user assets would not be affected, that the platform would absorb the losses, and that normal withdrawals resumed soon afterward.
According to ChainCatcher, Phemex appeared to have made advance arrangements to isolate risk before launching the AFX product. The two did not have a public connection at the brand or equity level, but the public record still showed multiple links between them.
With another loss now running into the tens of millions of dollars, the report said it remains unclear whether this was another operation by North Korean hackers or a case involving insiders. It added that more evidence and analysis will be needed.

