AFX Suspicious Theft Case: Audit Report Full of Flaws, Behind the Scenes Company Suspected to be Crypto Exchange Phemex

CN
PANews
Follow
7 hours ago

Author: Gu Yu, ChainCatcher

Today, the cross-chain bridge of the decentralized perpetual contract exchange AFX was hacked, resulting in over $24 million in assets being stolen. According to the TVL displayed on Defillama, this amount is equivalent to the entire protocol being emptied.

Following the incident, AFX posted on X stating that it is closely collaborating with leading security firms, ecosystem partners, exchanges, and relevant authorities to monitor the flow of funds and support the ongoing investigation.

1. The audit report has numerous flaws

However, the painful lesson for AFX seems to have had prior warnings. The project officially launched its mainnet in May and released an audit report on June 3. After today's theft incident, multiple professional security personnel discovered significant issues with this report.

In the report, the security auditing company Zellic stated that it found 11 issues, of which two were critical, and six were of moderate impact.

"Given that this audit only covered a portion of the components that constitute the bridge protocol and lacked testing coverage for all security-critical paths, this is particularly important. This not only limits our ability to verify correctness but also limits AFX's future capability to maintain a secure system. Furthermore, a critical factor that urgently needs a re-audit is that we did not have the ability to run or interact in real-time or local environments at that time. This greatly restricted our capacity to verify functionality, explore edge cases, and assess system behavior beyond static reviews," Zellic wrote in the summary section.

According to Zellic's disclosure, the code it was able to access and verify only covered parts of the bridge protocol, failing to encompass the complete asset cross-chain process and could not be tested in a real running environment. This means that for the core functions of the cross-chain bridge such as asset custody, signature verification, and access control, the auditing agency could not actually provide a complete conclusion.

Zellic also specifically warned that even if the project team completes vulnerability fixes based on the report, the auditing agency cannot confirm whether these fixes were properly implemented, nor can it guarantee that the fixing process would not introduce new vulnerabilities. This means that the report cannot actually serve as proof that the bridge protocol is 'safe', but rather resembles a phase inspection result for some parts of the code.

For a cross-chain bridge managing tens of millions of dollars in assets, "incomplete audit scope" itself is a risk. When the auditing agency cannot confirm the security boundaries of the entire system, users find it difficult to judge the true security of the protocol.

In response, Taylor Monahan, Chief Product Manager at MetaMask and founder of MyEtherWallet and MyCrypto, tweeted that the AFX cross-chain bridge audit report is "terrifying," indicating that numerous "confirmed" issues were left unaddressed, and expressed extreme disbelief over users transferring over $24 million into the protocol.

"This audit strongly points to a team that fundamentally does not care about being responsible for a 'not entirely a true M of N system.' Unaddressed edge cases? No problem. Manually handling user funds? No problem. Completely relying on team intervention to prevent being robbed? No problem."

Taylor Monahan speculated that AFX likely has all validators and keys on the same system or controlled by a single person.

2. The parent company suspected to be Phemex

ChainCatcher reporters further investigated the AFX team and found that the project seems to be closely related to the cryptocurrency exchange Phemex, and that Phemex is likely its parent company.

The intricate connections among team members serve as supporting evidence. The previous bio of AFX growth manager Ken's X account was "Head of Listing @phemex_official," the listing manager for Phemex, which is one of the core functional positions at any exchange.

Another team member Damon, who is also followed by AFX's official X account, does not have more public information but his X account was created 4 months ago and followed AFX's account, additionally following at least three other team members from Phemex.

Moreover, Phemex's official blog has published multiple articles promoting and introducing AFX, such as "Unlock Your Strength: Discover Why AFX Protocol Transforms Lives," "The Philosophy of Anti-Fragility: Why AFX Protocol Matters," "Dive into the Multi-Asset Perps Revolution!" and "Top 5 Perpetual DEXs to Watch in 2026." In the last article, AFX is also prominently featured ahead of other Perp DEXs like Hyperliquid.

Currently, the aforementioned articles have been deleted from Phemex's official website, but these articles still appear in search results when searching for their titles on Google.

Another correlating evidence is that the logos of the two projects share a very similar thematic style, both using a gradient color scheme from fluorescent green to teal against a pure black background, with nearly identical visual atmosphere and tonal orientation, which may also reflect that they have the same design team.

Based on the team's resumes, official historical promotions, brand designs, and public operational traces, AFX has a far closer relationship with Phemex than that of ordinary ecosystem partners.

The most thought-provoking issue is that Phemex was also hacked in January 2025 for over $70 million, which analysts at the time suggested was likely the work of North Korean hackers. At that time, the Phemex team stated that user assets would not be affected, the platform would absorb the losses caused by the incident, and soon restored the normal withdrawal process.

During the launch of the AFX product, Phemex obviously prepared for risk isolation in advance, and there are no public links between the two on brand, stocks, or other levels, yet the close relationship between the two cannot be concealed.

Now, the tragedy of losing tens of millions of dollars has recurred. Whether this is a repeat of North Korean hackers' methods or an insider setup to harvest remains dependent on more evidence and analysis.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink