AFX Trade Bridge Drained of $24.15M USDC on Arbitrum, Attacker Swaps for 12,467 ETH
Highlights
- An attacker drained exactly $24.15M in USDC from AFX Trade's custody bridge on Arbitrum, likely via compromised validator hot keys.
- The stolen USDC was bridged to Ethereum through Circle's CCTP and swapped for 12,467 ETH at roughly $1,937 each.
- Offchain Labs confirmed Arbitrum's native bridge was untouched, while AFX suspended operations and offered a 30% white-hat bounty.
The AFX Trade Bridge exploit has sent shockwaves across the DeFi space. On July 22, 2026, an attacker drained exactly $24.15 million in USDC from a custody bridge operated by AFX Trade on Arbitrum.
Security firm Blockaid detected the breach at approximately 21:30 UTC, confirming that the attack was specific to an AFX Trade bridge exploit and did not touch Arbitrum’s native bridge.
Inside the $24.15M Raid on AFX’s Arbitrum Bridge
AFX Trade runs a decentralized perpetual futures protocol on a sovereign Layer-1 chain. It routes USDC deposits through Arbitrum via a custom custody bridge, and that bridge became the target.
On-chain data shows that at 21:30:25 UTC, the attacker triggered a successful withdrawal of exactly 24,150,000 USDC from the bridge contract.
Preliminary on-chain analysis suggests the attacker may have compromised validator hot keys, meeting the 5-of-7 signature quorum required to authorize the withdrawal.
After the drain, the attacker bridged the stolen USDC to Ethereum via Circle’s CCTP and swapped it for 12,467 ETH at an average price of roughly $1,937 per ETH.
AFX Trade(@AFX_XYZ) was exploited for $24.15M!
The exploiter bridged 24.15M $USDC to #Ethereum and bought 12,467 $ETH at an average price of $1,937.https://t.co/m5i1x1EOlz pic.twitter.com/XWD4dWLlJc
— Lookonchain (@lookonchain) July 23, 2026
The conversion into ETH exposed the stolen value to price risk and complicated recovery efforts.
This incident is not isolated. Just one day before the AFX breach, attackers hit the Wanchain-Cardano Bridge and walked away with $13M, proof that cross-chain infrastructure keeps drawing fire in 2026.
Offchain Labs co-founder Steven Goldfeder was quick to separate AFX’s incident from Arbitrum’s core infrastructure.
“We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Goldfeder stated on X.
We're aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way.
We will coordinate with the third…
— Steven Goldfeder (@sgoldfed) July 22, 2026
AFX immediately suspended bridge operations after the breach.
Security Is Not a Feature, It Is the Product
BloFin CEO Matt responded to the AFX Trade bridge exploit with a blunt industry warning: X: “24M drained from a protocol-run bridge on Arbitrum today. The canonical bridge held; the custom one didn’t… in this industry, security isn’t a feature you add later. It IS the product.”
24M drained from a protocol-run bridge on Arbitrum today. The canonical bridge held, the custom one didn’t.
Every cycle we relearn the same thing: in this industry, security isn’t a feature you add later. It IS the product. Yield, speed, UX, none of it matters if user funds… https://t.co/8UCi73NOE0— Matt (@BloFin_CEO) July 23, 2026
Bridge exploits have become a defining threat of 2026. A flash loan exploit hit Summer.fi Vaults in July. Also, a Private Keys Hack Drained the Humanity Protocol in a similar custody-key scenario earlier this year.
The KelpDAO incident in April saw attackers drain roughly $292 million via a LayerZero-powered bridge, a case CoinGape reported showed North Korea’s Lazarus Group was blamed for the KelpDAO LayerZero exploit.
AFX has issued a white-hat bounty offer, return 70% of the funds and keep 30%. The protocol has enlisted SlowMist, Zellic, and the Crypto Defense Alliance to assist in the investigation, per their official update.
We are continuing to work closely with leading blockchain security partners as the investigation progresses. According to SlowMist, the stolen funds remain in the attacker's address and have been reported to the Crypto Defense Alliance (CDA), a collaborative network that includes…
— AFX Trade (@AFX_XYZ) July 23, 2026
AFX has confirmed no recovery at the time of writing. This incident sends a direct custody warning to investors in perp DEXs.
The investigation into the AFX Trade bridge exploit continues. Users should monitor official AFX channels for updates on deposits, withdrawals, and any recovery plan.
Swap tokens instantly without an order book using these top crypto swap platforms.











