Aftermath Finance Postmortem: The Audit Missed It, the Attacker Did Not
Aftermath Finance released its full incident postmortem on May 1, 2026. The report names the bug, traces where it came from, and maps exactly where the stolen funds landed. It is the clearest public accounting of a DeFi exploit published this month.
The flaw was a signed integer issue in the integrator accounting logic for AFperps, the protocol's perpetuals product on Sui. It was introduced on August 29, 2025. A formal audit by OtterSec reviewed it in November 2025. The audit did not flag it. The code ran in production for five more months before an attacker found and exploited it on April 29, 2026.
The attacker funded a wallet on April 28 with 405.24 SUI, swapped 300 SUI for roughly 278 USDC the next morning, then opened seventeen transactions between 08:55 and 09:31 UTC. Six failed. Eleven worked. Every successful transaction used the same Programmable Transaction Block structure: register as your own integrator with a negative taker fee, execute a market order, withdraw synthetic collateral as real USDC. No adaptation. Same structure every time.
Total drained: 1,139,927 USDC across 36 minutes.
After the drain, the attacker moved funds through single-use wallets and DEX swaps before depositing to four exchanges. Approximately $400K USDC went to KuCoin. Around $250K USDC went to Binance. Roughly 150,000 SUI went to Huobi/HTX. About $150K USDC went to HitBTC. All wallet addresses are publicly traceable on SuiVision.
Aftermath confirmed all users will be compensated fully. AFperps will not relaunch until a new audit is complete, and the team explicitly stated the relaunch audit will go to a different company. The team also said manual review alone is insufficient in 2026 and announced investment in AI-driven security workflows.
This happened during the worst month for DeFi hacks on record. April 2026 saw $629 million in total losses across the sector.
The full postmortem breakdown, including all on-chain addresses and the exact PTB transaction structure used in each successful drain, is at CryptoNewsLive.org.
Full report: CryptoNewsLive.org
Comments
Post a Comment