HomeZ - Banner home engArbitrum AFX Exploit: $24M Drained, Hacker Offered 30% Bounty

Arbitrum AFX Exploit: $24M Drained, Hacker Offered 30% Bounty

A decentralized perpetuals exchange built on Arbitrum just lost nearly everything it had. AFX Trade, which runs on the Arbitrum layer-2 network and settles positions in USDC, was drained of $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol itself operates — not the underlying network.

Key takeaways

  • AFX Trade lost approximately $24.15 million in a bridge exploit targeting validator signing keys on its USDC custody bridge.
  • The stolen USDC was moved to Ethereum and swapped for 12,468 ETH, now sitting in a single wallet, according to PeckShield.
  • Arbitrum’s native bridge was not affected; co-founder Steven Goldfeder confirmed it “has not been hacked or exploited in any way.”
  • AFX immediately suspended the compromised bridge and offered the attacker a deal: return 70% of the stolen funds and keep 30% as a “white hat bounty.”
  • Security firms Blockaid and PeckShield are actively monitoring and tracing the stolen assets; the exact attack vector is still under investigation.

AFX Trade Suffers $24 Million Bridge Exploit

The Arbitrum AFX exploit is a sharp reminder of where DeFi’s real vulnerability often lives — not in smart contracts, but in the off-chain infrastructure surrounding them. According to blockchain security firm Blockaid, which flagged the incident at 21:30 UTC on July 22, the attack was specific to a bridge AFX operates. The smart contract itself functioned exactly as designed: it verified the signatures and released the funds. The problem was that the private validator signing keys authorizing those signatures had been compromised.

Blockaid detailed that five of the bridge’s hot-validator signatures — meeting the roughly two-thirds quorum the bridge requires — signed off on moving 24,150,000 USDC to the attacker’s wallet. After a 200-second dispute period, the contract treated the withdrawal as valid and released the funds. The bridge did precisely what it was built to do. The keys were just in the wrong hands.

Details of the Exploit and Asset Movement

Once the funds cleared, the attacker moved quickly. The stolen USDC was bridged from Arbitrum to Ethereum and swapped for approximately 12,468 ETH — worth roughly $24 million at the time — all consolidated into a single wallet, according to on-chain tracking by PeckShield.

That figure is significant for another reason: according to DefiLlama data cited by CoinDesk, the $24.15 million drained represented nearly the entirety of AFX’s total value locked. The attacker emptied the vault close to the moment it was fullest, as AFX had been seeing daily perpetuals volume spike to multi-month highs in mid-July.

Immediate Response and Operational Impact

AFX suspended the compromised bridge immediately upon detecting the incident and initiated incident response procedures. In a public statement, the protocol said the damage appeared “isolated to the AFX-operated custody bridge,” with neither its trading infrastructure nor the Arbitrum mainnet compromised. Engineering and security teams are actively investigating the root cause, though the precise attack vector has not been publicly confirmed.

AFX also said it is working with ecosystem partners and security firms — including Blockaid and PeckShield — to trace the stolen assets.

Clarification on Network Security and Scope

The Arbitrum native bridge was not breached. That distinction matters enormously, and Arbitrum moved swiftly to make it clear.

Statements from Arbitrum Co-founder

Steven Goldfeder, co-founder of Offchain Labs — the team that develops and maintains Arbitrum — confirmed on X that the network’s native bridge “has not been hacked or exploited in any way” and that the transaction originated from a third-party protocol. A compromise of Arbitrum’s own bridge would send risk signals across the entire layer-2 ecosystem; a compromised application running on top of it is a contained failure, even if a painful one.

Distinction Between AFX Bridge and Arbitrum Network

This is the kind of distinction that rarely gets enough attention during a crisis. Bridges are blockchain tools for transferring tokens between networks, and protocols frequently deploy their own. When a protocol-operated bridge is compromised through key theft, nothing in the underlying network’s code is broken. The exploit belongs to the application layer, not to Arbitrum itself.

Still, the incident adds to a difficult stretch for Arbitrum-based protocols. An oracle exploit drained a separate $18 million from RWA platform Ostium just one week earlier, according to CoinDesk. Q2 2026 has already been flagged as among the worst quarters on record for crypto security, according to a report by Hacken — and most of the major hacks this year have targeted off-chain components rather than smart contracts.

Response Strategy Including White Hat Bounty Offer

AFX’s Public Offer to the Attacker

Hours after the exploit, AFX’s head of growth, Ken C, made a public offer to the attacker: return 70% of the stolen funds and keep the remaining 30% as a “white hat bounty.” It’s a well-worn playbook in crypto — a public plea designed to give the attacker a legal exit while recovering the bulk of user funds.

The approach has precedent. Solana’s Drift Protocol used the same tactic after its roughly $285 million hack in April, where attackers had spent months working toward privileged access rather than breaking any contract logic. Whether the strategy works depends entirely on whether the attacker prefers a clean exit over the complexity of laundering a nine-figure sum.

Investigation Status and Security Efforts

The exact method by which the validator signing keys were compromised remains unknown. AFX’s engineering and security teams are investigating, and Blockaid is coordinating with the Arbitrum team on the response. The on-chain trail is clear — the funds sit in a single Ethereum wallet — but the off-chain sequence that led to the key compromise has not yet been disclosed.

That gap matters beyond this incident alone. Key-compromise attacks are methodical by nature; the Drift Protocol case showed that attackers can spend months gaining privileged access before acting. If the AFX attacker followed a similar pattern, the question of how long the keys were exposed — and what else may have been accessible — remains open. For every protocol operating a bridge with hot validators, the AFX exploit is an uncomfortable prompt to audit not just the code, but everything around it.

FAQ

What part of AFX Trade was exploited in the hack?

The exploit targeted the USDC custody bridge operated by AFX Trade, not the Arbitrum network or its native bridge. Attackers compromised the validator signing keys used to authorize withdrawals from that bridge.

How much money was stolen in the AFX Trade exploit?

Approximately $24.15 million was stolen in the exploit, representing nearly the entirety of AFX Trade’s total value locked at the time.

What has AFX Trade done in response to the incident?

AFX Trade immediately suspended the compromised bridge and initiated incident response procedures. The engineering and security teams are actively investigating the attack vector, while security firms Blockaid and PeckShield are helping trace the stolen assets.

What offer did AFX make to the attacker?

AFX offered the attacker a deal to return 70% of the stolen funds and keep the remaining 30% as a “white hat bounty.” The offer was made publicly by AFX’s head of growth, Ken C.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Alessia Pannone
Graduated in communication sciences, currently student of the master's degree course in publishing and writing. Writer of articles from an SEO perspective, with care for indexing in search engines.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST