A goodwill plan is a start.. but it still doesn’t address the core questions.
Why the continued silence on the clear infrastructure, developer, and team overlaps with @Phemex_official?
Users lost $24M. The public evidence is still sitting there unanswered.
Findings:
https://t.co/6h5gGq9Klw
@Art0fDeFi@Phemex_official@AFX_XYZ Technical evidence pointing to a connection, they cannot hide it. Why are they not communicating with their community?
4/
Users lost $24 million.
Public evidence of overlapping infrastructure, developer accounts, promotional history, shared API naming, and now timed repository changes continues to surface.
@AFX_XYZ@Phemex_official
When does the silence end?
And when does a clear path to full compensation for the victims actually begin?
3/
A brand-new project does not normally inherit an unusual numbering scheme like “api10” that already exists on an established exchange.
It does not normally share the same internal developer domain used by that exchange.
And it does not normally rewrite public Git history the moment those links become visible.
So the question remains simple:
If there is no meaningful connection, why does the pattern keep expanding - and why does the cleanup happen precisely when attention increases?
2/
Even more striking is the timing.
On and around July 24 - right after the $24M exploit and as the https://t.co/RPgLVy2HFP connections started circulating - multiple AFX GitHub repositories were heavily updated.
Why force-push the commit history at that exact moment?
Why replace the original https://t.co/RPgLVy2HFP emails with https://t.co/tIMTWhRqPC addresses while keeping the same timestamps and messages?
What exactly needed to be cleaned up so quickly?
1/ 🚨 Day 8.
And the questions only keep growing.
Why does RootData still list @Phemex_official as @AFX_XYZ 's parent company?
Why were the official AFX SDKs originally committed from the internal https://t.co/RPgLVy29Qh domain - the same domain tied to older Phemex infrastructure?
And why do both platforms use the exact same unusual production endpoints - https://t.co/a9jCqTNQNN and https://t.co/kD7u1JEMMV - while api1 through api9 simply do not exist on either side?
@Art0fDeFi @0xkaiwonderland @Phemex_official@AFX_XYZ Phemex was praising AFX very much in their blog. As a long-time Phemex customer, I invested $20,000 in the AFX DeFi vault based on that, and now my savings are supposed to simply be gone through no fault of my own? Phemex as parent company should compensate these losses.
5/ @Phemex_official@AFX_XYZ
Day 7 and the pattern is becoming clearer.
The more people dig, the more things get removed.
When does the silence and scrubbing stop...
and when does full compensation for the victims actually start?
4/ Users lost $24 million.
Instead of transparency or compensation, we’re watching public traces of the relationship slowly vanish.. while key people stay active on the AFX side.
How many more “coincidences” need to disappear before @Phemex_official and @AFX_XYZ finally address this directly?
3/ This fits a growing pattern:
- Phemex blog posts promoting AFX → deleted after the exploit
- News articles about the incident → pulled
- Developer domain & infrastructure overlaps → never addressed
- And now a public BD profile that openly connected both projects → gone
Every time more evidence surfaces, something else gets cleaned up.
2/ Meanwhile, in AFX’s Discord she is still fully active…
…and holds Moderator status.
So the public-facing link gets scrubbed, but the internal role at AFX remains.
Interesting timing.
1/ 🚨 BREAKING
Another piece just quietly disappeared.
@0xkaiwonderland ... @phemex_official BD and self-described “early contributor at @afx_xyz " has now deleted (or completely rebranded) her X account.
She was publicly listing both roles until very recently.
Why remove it right after the connection between Phemex and AFX started getting attention?
@Art0fDeFi@AFX_XYZ@Phemex_official Phemex was praising AFX very much in their blog. As a long-time Phemex customer, I invested $20,000 in the AFX DeFi vault based on that, and now my savings are supposed to simply be gone through no fault of my own? Phemex as parent company should compensate these losses.
5/ @AFX_XYZ@Phemex_official
Day 6.
The evidence is public.
The reserves are public.
The precedent is public.
When is full compensation coming for the victims?
Or is continued silence your only answer?
4/
How long do you plan to pretend there are no personnel, technical, and promotional overlaps?
Why were the Phemex blog posts that heavily promoted AFX deleted immediately after the exploit? Is this still “coincidence”.. or systematic distancing?
2/
Why does RootData list Phemex as AFX’s parent company?
Why were AFX’s official SDKs committed from Phemex’s internal https://t.co/RPgLVy29Qh domain?
Why do both platforms use the exact same unusual API numbering (only api10 exists - 1 through 9 never did)?
Full public evidence with sources here:
https://t.co/zm4XnvpjwI
1/ @AFX_XYZ@Phemex_official
🚨 Day 6.
$24 million of user funds are still gone.
Why are you still silent?
When will you finally make the victims whole?
Or are you counting on people simply giving up?
3/
Why did Phemex fully absorb a larger ~$70 million hot-wallet hack in 2025 and make users whole.. yet remain completely silent while $24 million in AFX user funds are still missing on Day 6?
Why do Phemex’s own July 2026 Proof-of-Reserves continue to show 127%+ average coverage?
If the capacity is clearly there, why is there still no path to full compensation for the victims?