AFX Trade, a decentralized perpetuals exchange on Arbitrum that settles in USDC, was drained of roughly $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol operates. Security firm Blockaid detected the exploit at 21:30 UTC and said the on-chain logic was not bypassed: instead, five of the bridge's hot-validator signatures met the two-thirds quorum needed to authorize the withdrawal, which then cleared a 200-second dispute period before the funds released. The attacker bridged the stolen USDC to Ethereum and swapped it for about 12,467 ETH, nearly all of which now sits in a single attacker wallet.
Why it matters
Steven Goldfeder, co-founder of Arbitrum developer Offchain Labs, stressed that the network's native bridge was not breached and that the transaction originated from a third-party protocol. That distinction matters for the layer-2 at large: a native-bridge exploit would have signaled systemic risk across every Arbitrum-based application, while a compromised protocol running on top is a contained failure. The bridge's code did exactly what it was designed to do; the keys authorizing the withdrawal were simply in the wrong hands. The pattern mirrors the roughly $285 million Drift Protocol loss in April, where attackers spent months earning privileged access rather than breaking any contract.
Market impact
The loss lands amid a punishing stretch for crypto security and a concentrated run on Arbitrum-based protocols. The $24 million drained was almost the entirety of AFX's total value locked, and DefiLlama data shows the protocol's perpetuals volume had spiked to multi-month highs in mid-July as it drew in users and deposits. With the vault emptied at close to its fullest, recovery for users will depend on whether the protocol team can negotiate, trace, or claw back the swapped ETH before it moves further. A separate Arbitrum-based protocol, RWA platform Ostium, lost roughly $18 million to an oracle exploit a week earlier, leaving the network absorbing two significant incidents in quick succession.
Frequently asked questions
-
Was Arbitrum's native bridge hacked in the AFX Trade exploit?
No. Offchain Labs co-founder Steven Goldfeder said the Arbitrum native bridge was not breached and that the transaction originated from a third-party protocol that operates its own bridge.
-
How did the attacker drain AFX Trade without breaking the bridge code?
Security firm Blockaid said the on-chain logic worked as designed. Five hot-validator signatures met the two-thirds quorum needed to authorize the withdrawal, which then cleared a 200-second dispute period.
-
How much was stolen and where did the funds go?
About 24.15 million USDC was drained. The attacker bridged the USDC to Ethereum and swapped it for roughly 12,467 ETH, worth around $24 million, now sitting in a single attacker wallet.
-
How badly did this hurt AFX Trade users?
The loss represented almost the entirety of AFX's total value locked, and DefiLlama data showed the protocol's perpetuals volume had spiked to multi-month highs in mid-July, meaning the vault was emptied close to its fullest.
-
Does this fit a broader pattern of Arbitrum-based exploits?
Yes. A separate Arbitrum-based RWA platform, Ostium, lost roughly $18 million to an oracle exploit a week earlier, and the AFX attack echoes the roughly $285 million Drift Protocol loss in April, where attackers earned privileged access rather than breaking any contract.
CoinDesk