AFX Bridge Exploit Drains $24.15M USDC as Attacker Converts Funds Into 12,467.5 ETH
Key Takeaways
- •Blockaid said the exploit targeted an AFX-operated bridge and drained approximately 24.15 million USDC on July 22.
- •Offchain Labs said the suspicious transaction came from a third-party protocol and that Arbitrum’s native bridge was not hacked.
- •PeckShield reported that the attacker moved the stolen funds to Ethereum and swapped them for 12,467.5 ETH.
- •AFX had not published a verified technical postmortem or announced a recovery plan at publication time.
- •Investigators are examining the AFX bridge and the authorization process behind the USDC withdrawal.

AFX suffered a $24.15 million USDC loss after an attacker targeted a cross-chain bridge connected to the trading protocol on July 22, while Arbitrum’s native bridge remained unaffected.
The incident prompted an investigation by Blockaid and the Arbitrum team, as on-chain trackers followed the stolen funds from Arbitrum to Ethereum. The exploiter later converted the proceeds into 12,467.5 ETH.
AFX operates its own sovereign Layer 1 for perpetual trading and accepts USDC deposits through Arbitrum. The affected infrastructure was a third-party bridge operated by AFX, not Arbitrum’s core bridge.
AFX bridge loses $24.15 million USDC
Blockaid said it detected the exploit at 9:30 p.m. UTC on July 22. According to the security firm, the attack targeted a bridge operated by AFX and drained about 24.15 million USDC.
An Arbiscan record shows a successful transfer of 24,150,000 USDC from the bridge contract to the recipient address at 9:30:25 p.m. UTC.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ , a protocol on @arbitrum . The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol. Our team has been working with the incredible folks on… — Blockaid (@blockaid_) July 22, 2026
Blockaid said it was working with the Arbitrum team to respond to the incident, contact the affected protocol and help contain the stolen funds. Based on public updates reviewed at publication time, no recovery had been confirmed.
AFX had not published a verified technical postmortem explaining how the attacker gained authorization to withdraw the funds, and the protocol had not announced a recovery plan.
Offchain Labs co-founder Steven Goldfeder confirmed that the suspicious transaction originated from a third-party protocol and distinguished the AFX incident from Arbitrum’s own bridge infrastructure.
“We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Goldfeder said.
Goldfeder added that the team would coordinate with the third-party protocol and share more details when available. The distinction is important because applications can operate their own contracts and bridges on Arbitrum without those systems being part of Arbitrum’s native bridge.
AFX uses Arbitrum as a route for USDC deposits while running its trading system on a dedicated Layer 1. The protocol describes itself as a decentralized derivatives platform built around a sovereign execution environment. A recent protocol post also said users could deposit USDC from Arbitrum before accessing its perpetual markets.
Exploiter converts stolen USDC into ETH
PeckShield said the attacker moved the stolen USDC from Arbitrum to Ethereum and converted the proceeds into 12,467.5 ETH. Lookonchain separately reported that the exploiter bought about 12,467 ETH at an average price near $1,937 per ETH after moving the funds.
#PeckShieldAlert @AFX_XYZ on #Arbitrum has been exploited for ~$24M USDC. The exploiter has bridged the stolen funds from #Abitrum to #Ethereum and swapped them for 12,467.5 $ETH , currently sitting in 0x6276…ebAC. pic.twitter.com/fUHFfEn1F5 — PeckShieldAlert (@PeckShieldAlert) July 23, 2026
The conversion moved the stolen value from a U.S. dollar-pegged stablecoin into Ether, exposing the holdings to ETH price movements. Security teams continued tracing the funds after the swap.
At publication time, the reviewed sources did not confirm that Circle had frozen the USDC before conversion or that any of the ETH had been recovered.
The attack adds to several bridge-related security incidents this year. As crypto.news previously reported, Stake DAO closed its vsdCRV bridge after an unauthorized mint on Arbitrum in May. The project said it secured the token’s mainnet backing and contained the incident to the affected bridge.
Earlier in April, a larger exploit hit Kelp DAO’s LayerZero-powered bridge. Attackers drained roughly 116,500 rsETH worth about $292 million. Arbitrum later froze more than 30,000 ETH linked to that attacker after the funds moved onto Arbitrum One.
Investigation focuses on AFX-operated infrastructure
The investigation now centers on the AFX-operated bridge and the authorization process behind the 24.15 million USDC withdrawal. The confirmed transaction shows that the bridge contract finalized the transfer, but public statements have not yet established the verified root cause.
A full postmortem may determine whether the incident involved compromised validator credentials, faulty access controls or another weakness. The primary confirmed point is that the exploit affected infrastructure operated by AFX rather than Arbitrum’s native bridge.
Blockaid and Offchain Labs both made that distinction clear in their initial responses. The Arbitrum network continued operating, and reviewed reports showed no loss from its native bridge.
The incident also puts attention on AFX’s deposit infrastructure. The protocol has promoted USDC deposits from Arbitrum as an entry route into its trading platform. Any changes to deposits, withdrawals or bridge operations will depend on the protocol’s response and the ongoing investigation.
The case remains developing. The confirmed loss stands at about $24.15 million in USDC, while on-chain trackers have traced the stolen value into roughly 12,467 ETH on Ethereum. Further updates are expected from AFX, Blockaid and the Arbitrum team as they review the breach and track the attacker’s funds.