Recently, the AFX Trade cross-chain bridge, focused on multi-chain asset exchanges, was breached by hackers, with a single source reporting that the stolen assets amount to approximately 24.15 million USDC. Shortly after the attack occurred, funds were quickly “rearranged” on the Ethereum chain, where hackers concentrated this batch of USDC into about 12,467.4 ETH, consolidating originally scattered redemption assets from the bridge into positions that are easier to transfer across chains. Subsequent on-chain movements indicated that the event had progressed from "attack occurrence" to the more challenging "asset disposal stage": the same attacker address began to send some ETH into the cross-chain exchange protocol THORChain, where approximately 655.4 ETH has been detected being exchanged for about 18.86 BTC, with funds transitioning from the Ethereum ecosystem into the Bitcoin ecosystem. On-chain analyst Yu Jin highlighted this ETH to BTC exchange path through THORChain on social media, exposing the follow-up flow of this attack clearly in the public eye. To the outside, this was a passive witness - exposing a security vulnerability on one end of the cross-chain bridge while hackers used the other end of the cross-chain liquidity protocol as a "laundering channel." Both are part of the infrastructure yet played dual roles as the attack entry point and retreat path in the same event, upgrading the original tracking difficulty concentrated on a single chain to a long-term game crossing multiple public chains and protocols.
First Round of Exchanges After the Theft of 24.15 Million USDC
Looking back at the window just after the attack occurred, the starting point of this event was actually very "simple and crude": according to information from a single source, after the AFX Trade cross-chain bridge was compromised, the attacker address amassed around 24.15 million USDC in substantial positions on Ethereum. Almost immediately, this address opted not to test the waters in small batches, but rather initiated a one-time large exchange operation, concentrating all or most of the stolen USDC into approximately 12,467.4 ETH (around 12,467.4 ETH), reflecting a concentrated value reorganization on-chain.
Switching from dollar-pegged tokens to ETH is a common "first disposal action" seen in many historical attack cases. Such tokens have a stronger tether to the real financial system, while ETH, as a mainstream on-chain asset, has richer on-chain usage scenarios and cross-chain paths. Concentrated exchanges can quickly complete the migration from a bookkeeping unit to a native asset form. In the case of AFX Trade, the generation of this approximately 12,467.4 ETH marked the formal transition of funds from the stolen status of the cross-chain bridge into a multi-staged disposal process involving further cross-chain conversion and splitting.
655 ETH Exchanged for Nearly 19 BTC
After completing the concentrated conversion of USDC into about 12,467.4 ETH, the same attacker address began to dispose of a portion of the ETH. On-chain monitoring showed that this address sent approximately 655.4 ETH to exchange paths related to THORChain, which were subsequently exchanged for approximately 18.86 BTC in that cross-chain exchange protocol, signaling that a portion of the stolen assets officially left the Ethereum ecosystem and entered the Bitcoin network. According to AiCoin data, this step has moved beyond simple asset replacement within the same chain and completed the exchange between native assets through an unpermissioned cross-chain liquidity protocol.
From a procedural perspective, this was a continuous action by the hacker that aggregated the stolen USDC into ETH on the bridge and then split off a portion to cross-chain exchange into BTC. The migration from ETH to BTC signifies a transfer of funds from an account model chain to a UTXO model chain, fundamentally altering the address system and transaction graph. For external trackers, the funding path is significantly lengthened, increasing the difficulty of analysis. As for why the hacker chose to switch to the Bitcoin ecosystem at this point, the current public materials only indicate the objective action of cross-chain exchange, with any judgments about cash-out methods or subsequent exit choices remaining speculative. In the absence of more confirmed addresses and transaction paths, this stage of conversion appears more like an intermediate step to increase technical tracking barriers rather than a clearly defined end intention.
THORChain as the Hacker's Cross-Chain Laundering Channel
THORChain is essentially a cross-chain liquidity protocol that allows native assets to be directly exchanged between multiple public chains. It supports multi-chain assets including Ethereum and Bitcoin, enabling users to exchange ETH for BTC without involving any centralized trading platforms. The entire process is automatically matched and settled by the protocol based on the liquidity in the pool, with the front end being a simple operation of "deposit ETH, withdraw BTC on another chain." Because it is a permissionless neutral infrastructure, THORChain both provides tools for ordinary users to avoid custody risks and reduce trust costs, while also inherently possessing potential risks of being exploited as an asset conversion and transfer channel in the context of security incidents.
In the on-chain path of the AFX Trade attack, this dual role is particularly direct. The same attacker address initially concentrated approximately 24.15 million USDC into about 12,467.4 ETH on Ethereum and then began disposing of a portion of the ETH: according to AiCoin data, about 655.4 ETH was sent to THORChain and exchanged for about 18.86 BTC, with funds crossing from the Ethereum ecosystem to the Bitcoin ecosystem. The hacker chose to complete the exchange from ETH to BTC through THORChain rather than via traditional exchanges, objectively utilizing the unpermissioned cross-chain tool to enhance asset conversion efficiency and increasing the technical tracking threshold through cross-chain and asset type switches. Similar decentralized cross-chain protocols have often been observed to act as tools for asset conversion and dispersion in past attack incidents, and this time THORChain similarly embedded itself as a passive yet key infrastructure node within the attack chain, shifting its position in security analysis from a background component to a core path that must be separately dissected.
Security Dilemma of Cross-Chain Bridges Frequently Under Attack
Within a broader narrative framework, AFX Trade is not an isolated incident. Cross-chain bridges serve as a hub for the aggregation and cross-chain transfer of multi-chain assets within the entire decentralized finance system, with large amounts of funds, complex logic, and cross-protocol calls folded into a single "intermediate layer" component, which has historically been the target of attacks multiple times. This time, the approximately 24.15 million USDC stolen from the cross-chain bridge by hackers and subsequently concentrated into about 12,467.4 ETH on Ethereum echoes the established model of “if a high-value, centralized asset component is compromised, the consequences can be greatly magnified”.
What is even more concerning is that the attackers did not stop at single-chain disposal; the stolen asset path has now crossed multiple asset forms and public chain ecosystems including USDC, ETH, and BTC: approximately 655.4 ETH was sent to THORChain and converted to approximately 18.86 BTC, with some funds moving from the Ethereum ecosystem into the Bitcoin network. For those attempting to track and potentially recover assets, this signifies that the traditional monitoring framework centered around a single chain and single asset is being forced to upgrade; in other security incidents, once funds enter the Bitcoin network cross-chain, subsequent tracking costs are often increased through further splitting. Whether the hackers will adopt a similar path in the AFX Trade event remains lacking in public on-chain evidence. Along with the reality that the current attack technical details, project responses, and law enforcement progress remain undisclosed, the security dilemma exposed by this case has evolved from being merely a code risk to a systematic test of cross-chain asset disposal and tracking capabilities.
Observation Points for Tracking the AFX Hacker's Subsequent Movements
The narrative surrounding this case still has critical gaps: no official response from AFX Trade, compensation plans, or detailed event reviews have appeared in the public domain, nor have the specific technical vulnerabilities exploited in the attack or hacker identity information been confirmed or disclosed. There is also a lack of reliable public sources indicating whether law enforcement agencies have intervened. This means that assessments regarding the hacker's capability boundaries, whether the attack is replicable, the project’s risk tolerance, and compliance pressures can only remain at a speculative level, with on-chain behavior itself becoming one of the few “hard clues”.
According to AiCoin data, hackers have concentrated the stolen assets into approximately 12,467.4 ETH and disposed of about 655.4 ETH through THORChain, exchanging for approximately 18.86 BTC, with on-chain analyst Yu Jin highlighting this ETH to BTC cross-chain exchange action on social platforms. Moving forward, several key observation points need to be focused on: first, whether the remaining large amount of ETH continues to be exchanged in batches through THORChain or other cross-chain tools; second, whether the assets post-cross-chain further split and gradually transfer to new addresses within the Bitcoin network; third, whether any links with existing hacker clusters or suspected service provider addresses emerge. Once similar paths are confirmed, the industry may be forced to make more conservative adjustments in areas such as cross-chain bridge security audits, risk control whitelists for cross-chain protocols, and norms for using unpermissioned liquidity, and whether these adjustments can keep pace with the hacker's asset disposal rhythm will directly determine the warning level of this case in the technical community and among project parties.
Join our community, let's discuss and become stronger together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。


