{"uid":"cap_hrg5eoAbl2JrFEiFo1h2-","slug":"tenjin-security-briefs-afx-bridge-incident-jfrog-artifact-repo-attack-3199c2c2","name":"Tenjin Security Briefs – AFX Bridge Incident & JFrog Artifact-Repo Attack Weekly","description":"AFX's bridge incident tied a 24.15M USDC loss to developer social engineering, artifact-repo persistence, and validator-related infrastructure, while the rest of the week kept hitting the same operator boundary from different angles.","url":"https://tenjin.blog/api/read/security-briefs/security-briefs-weekly-the-bridge-loss-started-in-jfrog","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_JxR7aWbbWj61BRYn1q-y9","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a paywalled security-brief article covering the AFX bridge incident (24.15M USDC loss via developer social engineering and JFrog artifact-repo persistence) and related operator-boundary attacks for that week.","exampleAgentPrompt":"Pull the Tenjin security brief on the AFX bridge incident — the one about the 24.15M USDC loss tied to developer social engineering and JFrog artifact-repo persistence — using handle 'security-briefs' and slug 'security-briefs-weekly-the-bridge-loss-started-in-jfrog'.","exampleUseCases":[{"title":"Research the AFX bridge hack","prompt":"Get me the Tenjin security brief about the AFX bridge exploit where attackers used JFrog artifact-repo persistence to steal 24.15M USDC — handle is 'security-briefs', slug is 'security-briefs-weekly-the-bridge-loss-started-in-jfrog'."},{"title":"Weekly DeFi security incident briefing","prompt":"Fetch this week's Tenjin security digest covering the bridge loss that started in JFrog, including the developer social engineering angle and validator infrastructure details — handle 'security-briefs', slug 'security-briefs-weekly-the-bridge-loss-started-in-jfrog'."},{"title":"Supply chain attack on crypto infrastructure","prompt":"I want to read the Tenjin article about how artifact-repo persistence in JFrog enabled the AFX bridge incident and what the operator boundary implications are — use handle 'security-briefs' and slug 'security-briefs-weekly-the-bridge-loss-started-in-jfrog'."}],"resultDescription":"Returns the full text of the weekly security brief article, including incident narrative, attack vector breakdown (social engineering, JFrog artifact-repo persistence, validator-related infrastructure), loss figures (24.15M USDC), and analysis of related operator-boundary attack patterns observed that week.","failureModes":["Payment not received or x402 challenge not satisfied — article access denied","Invalid handle or slug returns 404 not found","Slug 'latest' used with a handle rather than wallet address — not payable","Stale or removed article returns empty or error response","Network timeout on the blog's read API"],"whenToPreferThis":"Choose this endpoint when you specifically need the Tenjin weekly security brief covering the AFX bridge incident, JFrog supply-chain persistence, and related validator/operator-boundary attacks. It is the canonical paywalled article endpoint for this specific piece; prefer it over general web search when you want the full structured article text delivered directly and are prepared to settle the x402 micropayment.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:52:44.462Z","isFirstParty":false}