AFX Trade Loses $24M in Bridge Exploit While Arbitrum Itself Stays Untouched
Security

AFX Trade Loses $24M in Bridge Exploit While Arbitrum Itself Stays Untouched

July 25, 20263 min read

AFX Trade, a decentralized perpetuals exchange on Arbitrum, lost about $24 million after an exploit hit the bridge it operates for USDC withdrawals. The money was not stolen from Arbitrum itself but from a separate service AFX used to move funds between networks, so the trading platform kept running. AFX has already offered the attacker a deal that promises to return 70% of the funds in exchange for letting the attacker keep the rest as a "white hat bounty."

What Happened to AFX Trade?

On Wednesday, the attacker drained $24.15 million through the USDC bridge that AFX Trade itself operates. Security firm Blockaid was first to flag the breach, and the exchange confirmed the incident on social media and immediately suspended the bridge.

The exact attack vector has not been disclosed. AFX only said the incident was tied to the USDC custody bridge, and that its trading infrastructure and mainnet were not affected. The team added that it is continuing the investigation together with independent security specialists.

The gist: A hacker drained $24 million through a separate USDC bridge run by AFX Trade, not through the Arbitrum network or the exchange trading system itself.

Why the Bridge Got Hit, Not Arbitrum Itself?

Attacks like this have become a routine part of DeFi news. A new story about a hacked bridge or a compromised oracle shows up every few weeks, and AFX Trade joined the list right after Ostium, another protocol on the same network.

At first the story looked like Arbitrum itself had been hacked, since AFX Trade runs on that layer-2 network. Arbitrum co-founder Steven Goldfeder quickly pushed back, writing that the network's own bridge "has not been hacked or exploited in any way" and that the transaction came from a third-party protocol.

The distinction matters. A breach of Arbitrum's native bridge would have hit the entire layer-2 and its dozens of apps. Instead, a single exchange's own service was compromised, so the damage stayed contained and did not spread to other projects on the network.

  • Key point: Bridges between blockchains have stayed a favorite hacker target for years, because they hold large token reserves under the control of a relatively small team.
  • Custody bridges run by the protocol team itself add another layer of trust that can be broken.
  • When a bridge is isolated from the trading system, the damage does not spread to the rest of the exchange or network.
  • Ostium, another perp protocol on Arbitrum, lost $18 million to a compromised oracle just a week earlier.

The Stolen Funds Trail Leads to a Single Wallet

Blockchain analytics firm PeckShield traced the stolen funds and reported that the attacker moved the USDC to Ethereum and swapped it for 12,468 ETH. The full amount still sits in a single wallet that anyone can track on a blockchain explorer.

AFX said it is working with industry partners and security firms to trace where the assets go next. So far, the wallet holding 12,468 ETH has shown no signs of moving funds to an exchange, leaving the team time to negotiate.

AFX Trade: the numbers
Amount stolen$24.15M
Swapped for12,468 ETH
AFX offer70% back, 30% keep
2026 DeFi hack losses$840M+

Why Is AFX Offering the Hacker 30%?

A few hours after the breach, AFX's head of growth, Ken C, publicly offered the attacker a deal. He promised to return 70% of the stolen funds and let the attacker keep the rest as a "white hat bounty." That is a common move in crypto, where a protocol team tries to negotiate directly with an attacker instead of relying only on law enforcement.

Solana's Drift Protocol made a similar move in April 2026 after losing $285 million. The logic is simple. Chasing an anonymous wallet through the courts often drags on for years with no guarantee of getting the money back, while a direct offer sometimes works faster and cheaper for the protocol itself.

What Does This Mean for DeFi Users?

For AFX Trade traders, the main risk has already passed. The trading system and funds held on the exchange itself were not touched, only what moved through the separate bridge. But for DeFi as a field, the pattern keeps repeating. This exploit added to the more than $840 million the industry has already lost to hacks in 2026.

The episode points to a simple rule for users. Custody bridges and third-party services around a protocol carry their own risk, even when the main exchange or network stays intact. It is worth checking exactly which component your funds pass through before trusting it with a large sum.

Comments

Your email address will not be published. Required fields are marked *

or verify by email