AFX Strange Theft Case: Audit Report Full of Holes, Company Behind it Suspected to be Cryptocurrency Exchange Phemex

CN
链捕手
Follow
2 hours ago

Author: Gu Yu, ChainCatcher

Today, the decentralized perpetual contract exchange AFX experienced a hacker attack, resulting in over 24 million dollars in assets stolen. According to the total value locked (TVL) displayed by Defillama, this amount is equivalent to the entire protocol being drained in one go.

After the incident, AFX posted on X stating that it is working closely with leading security companies, ecosystem partners, exchanges, and relevant authorities to monitor fund movements and support the ongoing investigation.

1. The Audit Report is Full of Holes

However, AFX's painful lesson seems to have been foreseen. The project officially launched its mainnet in May and released its audit report on June 3. Following today’s theft incident, multiple professional security experts found significant issues with this report.

In the report, the security audit company Zellic reported 11 issues, two of which were critical, one highly impactful, and six moderate in impact.

“Given that this audit only covered part of the components that make up the bridge protocol, and there was a lack of test coverage for all security-critical paths, this is especially important. This not only limits our ability to verify correctness, but also restricts AFX's future ability to maintain security systems. Moreover, a critical factor that urgently requires re-auditing is that we did not have the ability to run or interact in a real-time or local environment at that time. This greatly limited our ability to verify functionality, explore edge cases, and evaluate system behavior beyond static review,” Zellic stated in the summary section.

Image

According to Zellic’s disclosure, the code it was able to access and verify only covered part of the bridge protocol's components and could not cover the complete cross-chain asset process, nor could it test in a real operational environment. This means that for the most critical paths of asset custody, signature verification, and permission control in the cross-chain bridge, the auditing agency could not provide a comprehensive conclusion.

Zellic also specifically warned that even if the project party completed vulnerability fixes according to the report, the auditing agency could not confirm whether these fixes were properly implemented, nor could it guarantee that new vulnerabilities would not be introduced during the fixing process. This means that the report could not actually serve as proof that the bridge protocol was already "secure," but rather as a phase check result for part of the code.

For a cross-chain bridge managing tens of millions of dollars in assets, the "incomplete audit scope" itself is a risk. When the auditing agency cannot confirm the security boundaries of the entire system, users find it especially hard to assess the actual security of the protocol.

In response, MetaMask's Chief Product Manager, MyEtherWallet and MyCrypto founder Taylor Monahan tweeted that AFX's cross-chain bridge audit report is “very terrifying,” with many “confirmed” issues unresolved, and expressed extreme confusion over users transferring over 24 million dollars into the protocol.

AFX Strange Theft Case: Audit Report Full of Holes, Suspected Backing Company is Crypto Exchange Phemex

“This audit strongly points to a team that fundamentally does not care about being responsible for an 'incomplete true M of N system.' Unhandled edge cases? No problem. Manual operation of user funds? No problem. Completely relying on team intervention to prevent being robbed? No problem.”

Taylor Monahan speculated that it is highly likely that all validators and keys are on the same system, or controlled by a single individual.

2. The Parent Company Suspected to be Phemex

ChainCatcher reporters further investigated the AFX team and found that the project appears to have a close connection with the cryptocurrency exchange Phemex, and it is very likely that Phemex is its parent company.

One of the supporting evidence is the intricate connections among team members. AFX’s growth director Ken’s previous X account bio was “Head of Listing @phemex_official,” which indicates that he was in charge of listing at Phemex, one of the most core functional positions at any exchange.

AFX Strange Theft Case: Audit Report Full of Holes, Suspected Backing Company is Crypto Exchange Phemex

Another team member followed by AFX's official X account, Damon, although there is no more public information, his X account was created 4 months ago and he has followed at least three team members from Phemex’s exchange account after following the AFX account.

AFX Strange Theft Case: Audit Report Full of Holes, Suspected Backing Company is Crypto Exchange Phemex

In addition, Phemex's official blog has published several articles promoting and introducing AFX, such as “Unlock Your Strength: Discover Why AFX Protocol Transforms Lives,” “The Philosophy of Anti-Fragility: Why AFX Protocol Matters,” “Dive into the Multi-Asset Perps Revolution!,” and “Top 5 Perpetual DEXs to Watch in 2026,” in the last of which AFX was prominently featured alongside other Perp DEXs like Hyperliquid.

AFX Strange Theft Case: Audit Report Full of Holes, Suspected Backing Company is Crypto Exchange Phemex

Currently, the aforementioned articles have been deleted from Phemex's official website, but links to these articles still appear in Google search results when searching their titles.

Another associative evidence is that the logo themes of the two projects are also very similar, both featuring a gradient from fluorescent green to turquoise, set against a pure black background, with nearly identical visual atmosphere and tonal orientation, which may reflect that they have the same design team.

AFX Strange Theft Case: Audit Report Full of Holes, Suspected Backing Company is Crypto Exchange Phemex

Based on team resumes, official historical promotions, brand design, and public operational traces, there seems to be a relationship between AFX and Phemex that goes far beyond ordinary ecological partners.

The most “chilling” question is that Phemex was also hacked for over 70 million dollars in January 2025, widely believed to be the work of North Korean hackers. At that time, the Phemex team stated that user assets would not be affected, and the platform would cover the losses resulting from this incident, quickly restoring normal withdrawal processes.

During the launch of the AFX product, Phemex was evidently prepared in advance for risk isolation; there are no public connections between the two in terms of brand, stock, and other levels, but it still does not obscure the intricate relationship between them.

Now, the tragedy of losing tens of millions of dollars has played out again. Is this a repeat act by North Korean hackers, or an internal insider scheme to harvest? More evidence and analysis are still required to clarify this.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink