AFX Trade Hit for $24M After Bridge Validator Keys Compromised on Arbitrum

AI Market Summary
AFX Trade on Arbitrum was drained for ~24.15M USDC after bridge validator signing keys were compromised, with stolen funds bridged to Ethereum and swapped into ~12,467 ETH. While Offchain Labs states Arbitrum's native bridge was not exploited, the incident reinforces elevated smart-contract and key-management risk for protocols on Arbitrum amid a broader surge in L2-related exploits, likely weighing on near-term risk appetite.
Impact level
● Medium
Affected assets
ARB/USDT-1.03%
AI Insight · ARB/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
AFX Trade, a decentralized perpetuals exchange that settles in dollar-pegged stablecoin USDC, was drained of about $24.15 million on Wednesday after an attacker obtained the validator signing keys for a bridge the protocol runs on Arbitrum, according to blockchain data. Steven Goldfeder, cofounder of Offchain Labs, the team behind Arbitrum's development and maintenance, said Arbitrum's native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol. A compromise of Arbitrum's own bridge would raise network-wide concerns for the layer-2, while a breach of a protocol built on top of it is viewed as a contained incident. The bridge's core code was not broken. Bridges are blockchain tools that enable token transfers across different networks. Security firm Blockaid said the attacker did not bypass onchain logic. Instead, five hot-validator signatures—the approvals required to authorize a withdrawal—signed a transfer of 24,150,000 USDC to the attacker's wallet, meeting the bridge's roughly two-thirds quorum requirement. Blockaid said it detected the exploit at 20260722 21:30 UTC targeting @AFX_XYZ on @arbitrum, and noted the issue was specific to an AFX-operated bridge. After a 200-second dispute window, the contract accepted the withdrawal as valid and released the funds. In other words, the bridge functioned as designed, but the authorizing keys were apparently compromised. Onchain trackers show the attacker then bridged the stolen USDC to Ethereum and swapped it for about 12,467 ETH, valued at roughly $24 million, now held in a single wallet. AFX activity had been accelerating into the incident. DefiLlama data shows daily perpetuals volume surged to multi-month highs in mid-July as the protocol attracted users and deposits. The $24 million loss represented nearly all of the protocol's total value locked, suggesting the attacker effectively emptied the vault near its peak balance. The episode adds to a difficult stretch for crypto security, with Q2 ranking among the worst quarters on record for hacks. It also follows a series of hits on Arbitrum-based protocols, including an oracle exploit that drained $18 million from the RWA platform Ostium a week earlier. Observers compared the pattern to the roughly $285 million Drift Protocol loss in April, where attackers reportedly spent months gaining privileged access rather than exploiting a flaw in smart-contract logic.