AFX Bridge Exploit Drains $24.15 Million in USDC as Attacker Converts Funds Into 12,467 ETH
Key Takeaways
- •AFX's cross-chain bridge was exploited on July 22, with an attacker stealing approximately $24.15 million in USDC.
- •Blockchain security firm Blockaid confirmed the vulnerability was limited to AFX's bridge infrastructure and did not impact the broader Arbitrum Layer 2 network.
- •The attacker moved the stolen USDC to Ethereum and converted it into approximately 12,467 ETH, likely to avoid potential asset freezes that Circle could impose on USDC holdings.
- •No portion of the stolen funds had been recovered or frozen as of the time of reporting, with security teams actively monitoring the attacker's wallet.
- •The breach raises total cryptocurrency hack losses for July to roughly $97 million, exceeding the approximately $75 million recorded in June.

A cross-chain bridge operated by decentralized finance protocol AFX was hit by a major security breach on July 22, when an attacker drained approximately $24.15 million in USDC. The incident ranks among the largest cryptocurrency exploits recorded this month.
Blockchain security firm Blockaid detected the attack and confirmed that the vulnerability was confined to AFX's proprietary bridge infrastructure rather than the underlying Arbitrum network. The broader Layer 2 network continued operating normally following the exploit. The exact technical cause has not yet been publicly disclosed. Cross-chain bridges have historically accounted for some of the largest losses in decentralized finance, including the $625 million Ronin Network breach in 2022 and the $320 million Wormhole exploit the same year, making them a recurring focal point for security researchers.
Attacker Moves Funds to Ethereum
According to blockchain security researchers, the attacker swiftly transferred the stolen USDC from Arbitrum to Ethereum and then swapped the assets into approximately 12,467 ETH. The conversion to ETH, a native blockchain asset without a central issuer capable of freezing balances, is notable because USDC issuer Circle maintains the technical ability to freeze addresses holding its stablecoin, a mechanism previously used in other exploit cases. On-chain tracking shows the converted funds were consolidated into a single Ethereum wallet, indicating the attacker moved quickly to minimize exposure to potential asset freezes or recovery attempts.
Security teams have been actively monitoring the wallet while coordinating with ecosystem participants to assess the full scope of the incident. At the time of writing, there was no confirmation that any portion of the stolen funds had been recovered or frozen.
Bridge Security Under Renewed Scrutiny
The breach highlights the persistent risks associated with cross-chain bridges, which have remained frequent targets due to the large pools of digital assets they hold while connecting multiple blockchain networks. Bridges have grown central to DeFi interoperability, allowing users to transfer tokens across chains that otherwise cannot natively communicate, but their complexity has repeatedly introduced exploitable attack surfaces.
The AFX incident pushes total cryptocurrency hack losses for July to approximately $97 million, exceeding the roughly $75 million recorded in June. The upward trend underscores that bridge security remains one of the industry's most pressing challenges, despite ongoing investment in audits, monitoring tools, and real-time threat detection systems.
Market participants are awaiting further updates from AFX regarding the root cause of the exploit, potential recovery efforts, and any compensation plans for affected users. The incident adds to a growing list of bridge-related security events that continue to test confidence in decentralized finance as protocols expand their cross-chain capabilities.