AFX Offers Hacker 30% White-Hat Bounty to Return $24 Million in Stolen Cryptocurrency
Key Takeaways
- •AFX suffered a security breach in which approximately $24 million in cryptocurrency was stolen.
- •AFX proposed a white-hat agreement allowing the hacker to keep 30% of the stolen funds if 70% is returned.
- •The settlement offer was communicated through AFX's official X account and an on-chain message sent directly to the attacker's suspected wallet address.
- •Similar white-hat negotiation tactics have been used by other crypto platforms, including Poly Network in 2021 and Euler Finance in 2023, with mixed results.
- •Crypto hacks resulted in over $3.8 billion stolen in 2022 and approximately $1.7 billion in 2023, according to Chainalysis data.

AFX, a cryptocurrency platform, has publicly offered a hacker a negotiated settlement following a recent security breach. The company proposed a white-hat agreement allowing the attacker to legally retain 30% of the approximately $24 million stolen, on the condition that 70% of the funds are returned.
AFX communicated the offer through its official X (formerly Twitter) account and also sent an on-chain message directly to the wallet address believed to be controlled by the attacker, making the proposal transparent and verifiable on the blockchain.
Negotiation Strategy
The approach represents a calculated yet high-risk fund recovery tactic previously used by other crypto platforms. By framing the proposal as a white-hat bounty, AFX aims to incentivize the attacker to act as a responsible security researcher rather than a malicious actor. The 30% reward is intended for identifying the vulnerability and returning the majority of the stolen assets, potentially averting a protracted legal battle and the permanent loss of user funds. On-chain messaging has become a standard tool in these scenarios, as it allows platforms to reach an otherwise anonymous attacker through the very blockchain infrastructure exploited during the theft.
This dual-channel communication method ensures the offer is both visible to the broader community and cryptographically verifiable.
Industry Precedent
Such negotiation tactics are not unprecedented in the cryptocurrency sector. In August 2021, cross-chain protocol Poly Network suffered a $610 million exploit—the largest DeFi hack at the time—and ultimately recovered nearly all funds after publicly appealing to the attacker and offering a white-hat bounty. More recently, in March 2023, lending protocol Euler Finance recovered approximately $197 million after extended on-chain negotiation with its attacker. However, outcomes are never guaranteed, as they hinge entirely on the attacker's willingness to cooperate; some platforms have seen white-hat offers ignored entirely.
The incident underscores the persistent security challenges confronting the crypto industry. According to Chainalysis, crypto hacks resulted in over $3.8 billion stolen in 2022 and approximately $1.7 billion in 2023, with smart contract vulnerabilities and private key compromises remaining primary attack vectors. These figures reinforce the critical role of robust security audits, bug bounty programs, and rapid incident response protocols for crypto platforms.
Implications for Users and the Market
For AFX users, the breach has created a period of uncertainty. While the return of 70% of stolen funds would represent a partial recovery, the 30% retained by the hacker constitutes a significant loss. The incident also raises broader questions about the platform's security infrastructure and its capacity to safeguard user assets. Users affected by such breaches typically face extended waiting periods, as fund recovery negotiations can take weeks or months, and some platforms have suspended withdrawals pending resolution.
For the wider crypto market, high-profile hacks and subsequent public negotiations can affect investor confidence and invite regulatory scrutiny. The on-chain nature of the negotiation adds a degree of transparency rarely seen in traditional finance, but it also lays bare the vulnerabilities inherent in blockchain-based systems.
Background: White-Hat Bounties Explained
A white-hat bounty is an offer extended by a platform to a hacker—typically after a security breach—to return stolen funds in exchange for a financial reward and legal immunity. The framework casts the attacker as a security researcher who identified a vulnerability.
As for whether this type of negotiation is common in the crypto industry, several DeFi protocols and exchanges have employed similar offers in the past with mixed results. Some have successfully recovered funds; others have not, as the outcome ultimately depends on the attacker's decision.
The crypto community is now watching closely to see whether the attacker will accept AFX's proposal.