AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny

N
News Editor
2026-07-25 10:55:08
Decentralized perpetuals exchange AFX lost more than $24 million after its cross-chain bridge was hacked, an amount that roughly matched the protocol’s full TVL on DefiLlama. After the incident, AFX said on X that it was working with security firms, ecosystem partners, exchanges and relevant authorities to monitor fund flows and assist the investigation. Attention quickly shifted to AFX’s June 3 audit report from Zellic. The report said 11 issues had been identified, including two critical findings, one high-severity issue and six medium-severity issues. Zellic also stated that the review covered only part of the bridge protocol, did not test all security-critical paths and could not be performed in a live or local runtime environment. That meant the firm could not fully assess core areas such as custody, signature checks and permission controls, nor confirm whether fixes were correctly implemented later. ChainCatcher also outlined several public clues suggesting a close relationship between AFX and crypto exchange Phemex, including team-account connections, now-deleted Phemex blog posts promoting AFX, and similarities in brand design. The report noted that Phemex itself was hacked for more than $70 million in January 2025, when outside analysis said North Korean hackers were the likely culprit. It added that more evidence would be needed to determine whether the latest case was another external attack or involved insiders.
AFXPhemexcross-chain bridgehackaudit reportZellicpolicy regulation

AFX, a decentralized perpetual futures exchange, lost more than $24 million after its cross-chain bridge was hacked on Friday. Based on DefiLlama TVL data cited in the report, the stolen amount was effectively large enough to drain the protocol.

After the breach, AFX said in a post on X that it was working closely with leading security companies, ecosystem partners, exchanges and relevant authorities to monitor the movement of funds and support the ongoing investigation.

Zellic audit faces sharp criticism after the hack

AFX launched its mainnet in May and published an audit report on June 3. After the theft, several security professionals said the report itself raised serious concerns.

In that report, security auditor Zellic said it found 11 issues, including two critical findings, one high-severity issue and six medium-severity issues.

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny 3

Zellic wrote in its conclusion: "Given that this audit covered only a subset of the components that make up the bridge protocol, and lacked testing coverage across all security-critical paths, this is particularly important. This not only limited our ability to verify correctness, but also limited AFX’s future ability to maintain the system securely. In addition, a key factor that urgently warranted a re-audit was that we were not able to run or interact with the system in either a live or local environment at the time. This significantly limited our ability to verify functionality, explore edge cases, and assess system behavior beyond static review."

According to Zellic’s disclosure, the code it could access and verify covered only some bridge components. It did not cover the full cross-chain asset flow and could not be tested in a real operating environment. That left the most sensitive paths in the bridge — asset custody, signature verification and permission controls — outside a complete conclusion.

Zellic also said that even if the project team fixed the issues listed in the report, the auditor could not confirm whether those fixes had been implemented correctly, nor whether new vulnerabilities had been introduced in the process. In practical terms, the report did not amount to proof that the bridge was secure. It was closer to a point-in-time review of only part of the codebase.

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny 4

For a bridge handling tens of millions of dollars in assets, an incomplete audit scope is a risk by itself. If the auditor cannot define the security boundary of the full system, users have little basis for judging the protocol’s actual safety.

Taylor Monahan, chief product officer at MetaMask and founder of MyEtherWallet and MyCrypto, said on X that the AFX bridge audit was "absolutely terrifying." She said many issues marked as "acknowledged" had not been fixed, and added that she could not understand why users had deposited more than $24 million into the protocol.

Monahan wrote: "This audit strongly points to a team that fundamentally does not care to be responsible for a system that isn’t really M of N. Unhandled edge cases? Fine. Manual handling of user funds? Fine. Total dependence on team intervention to avoid being robbed? Fine."

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny 5

She also speculated that AFX may have had all validators and keys on the same system, or under the control of a single person.

Public traces point to possible ties with Phemex

ChainCatcher said its review of the AFX team suggested the project had close links to crypto exchange Phemex, and that Phemex may even have been its parent company.

One supporting point came from public team profiles. Ken, AFX’s head of growth, previously described himself on X as "Head of Listing @phemex_official," a role the report described as one of the core functions at any exchange.

Another team-linked account followed by AFX’s official X profile belonged to Damon. While little public information was available about him, the report said his X account was created four months earlier, followed the AFX account, and also followed at least three X accounts belonging to Phemex team members.

There were also traces in Phemex’s own content. The exchange’s official blog had published several promotional articles about AFX, including Unlock Your Strength: Discover Why AFX Protocol Transforms Lives, The Philosophy of Anti-Fragility: Why AFX Protocol Matters, Dive into the Multi-Asset Perps Revolution! and Top 5 Perpetual DEXs to Watch in 2026. In the last article, AFX was placed ahead of other perpetual DEXs such as Hyperliquid.

Those articles have now been removed from the Phemex website. Even so, the report said the links still appear in Google search results when the titles are searched.

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny 7

Another point raised in the report involved visual identity. AFX and Phemex use closely related logo styles, with fluorescent green-to-teal gradients set against black backgrounds. The overall look and color direction are nearly the same, which the report said could indicate the use of the same design team.

Taking team backgrounds, historical promotion, brand design and operating traces together, ChainCatcher said the relationship between AFX and Phemex appeared to go well beyond that of ordinary ecosystem partners.

Phemex had its own major hack in January 2025

The report also pointed to an earlier incident at Phemex. In January 2025, the exchange lost more than $70 million in a hack. At the time, outside analysis said North Korean hackers were the most likely culprit.

AFX bridge hack tops $24 million as audit gaps and Phemex ties come under scrutiny 8

Phemex said then that user assets would not be affected, that the platform would absorb the losses, and that normal withdrawals resumed soon afterward.

According to ChainCatcher, Phemex appeared to have made advance arrangements to isolate risk before launching the AFX product. The two did not have a public connection at the brand or equity level, but the public record still showed multiple links between them.

With another loss now running into the tens of millions of dollars, the report said it remains unclear whether this was another operation by North Korean hackers or a case involving insiders. It added that more evidence and analysis will be needed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.