The hacker responsible for the recent AFX Trader exploit has moved a significant portion of stolen funds through the decentralized cross-chain liquidity protocol THORChain. On July 23, the attacker swapped 655.4 ETH for approximately 18.86 BTC, according to blockchain analyst EmberCN.
Timeline of the AFX Trader Exploit
The incident began on July 23, when AFX Trader, an Arbitrum-based decentralized finance protocol, lost $24.15 million in USDC through a bridge hack. The attacker quickly converted the stolen USDC into 12,467.4 ETH, a common tactic used to complicate tracking and avoid stablecoin blacklisting.
By using THORChain, the hacker leveraged a protocol that allows native cross-chain swaps without wrapping assets or relying on centralized intermediaries. This makes tracing and freezing funds more difficult for investigators.
White-Hat Negotiation Offer
In response to the breach, AFX Trader proposed a white-hat negotiation to the attacker. Under the terms, the hacker would be allowed to legally keep 30% of the stolen funds—approximately $7.24 million—in exchange for returning the remaining 70% of the assets to the protocol.
This type of negotiation is not unprecedented in the DeFi space, where protocols sometimes offer a bounty or a percentage of stolen funds as an incentive for hackers to return the bulk of the assets, avoiding further legal escalation.
Why This Matters for DeFi Users
The AFX Trader incident highlights ongoing security vulnerabilities in cross-chain bridges, which remain a prime target for attackers. The use of THORChain for fund movement also underscores the challenges faced by law enforcement and blockchain analytics firms in tracking stolen assets across multiple blockchains without centralized oversight.
For DeFi users and investors, this event serves as a reminder to exercise caution with protocols that have not undergone rigorous security audits, and to remain aware of the risks associated with bridge liquidity pools.
Conclusion
The AFX Trader hacker’s continued movement of stolen funds through THORChain adds another layer of complexity to an already challenging recovery effort. While the white-hat negotiation offer remains open, the attacker has not yet responded publicly. The broader DeFi ecosystem continues to grapple with the balance between decentralization and security, as bridge exploits remain one of the most costly attack vectors in crypto.
FAQs
Q1: What is THORChain and why did the hacker use it?
THORChain is a decentralized cross-chain liquidity protocol that allows users to swap native assets across different blockchains without wrapping tokens or using a centralized exchange. The hacker used it to convert ETH to BTC in a way that is harder to trace or freeze.
Q2: How much was stolen in the AFX Trader exploit?
The attacker stole $24.15 million in USDC from the AFX Trader bridge on Arbitrum. The funds were later converted to 12,467.4 ETH, and a portion of that has now been swapped for Bitcoin.
Q3: What is a white-hat negotiation in crypto?
A white-hat negotiation is an offer made by a protocol to a hacker, typically allowing the hacker to keep a percentage of stolen funds in exchange for returning the rest. This is often done to recover assets without involving law enforcement, though it remains a controversial practice.
Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

