NewsCryptoAFX Bridge Exploit Drains $24.15M in USDC, Attacker Converts Stolen Funds to Ethereum

AFX Bridge Exploit Drains $24.15M in USDC, Attacker Converts Stolen Funds to Ethereum

Author: Tron Weekly·

Key Takeaways

  • AFX's cross-chain bridge was exploited on July 22, 2026, resulting in the loss of 24.15 million USDC from the protocol's bridge contract.
  • The attack was confined to a third-party bridge operated by AFX and did not affect Arbitrum's native bridge infrastructure, which remains fully operational.
  • The attacker transferred the stolen USDC to Ethereum and converted the proceeds into approximately 12,467.5 ETH at an average price of $1,937 per ETH to evade potential asset freezing.
  • Blockchain security firms Blockaid and PeckShield, along with Offchain Labs co-founder Steven Goldfeder, confirmed that investigations are underway but no assets have been recovered and AFX has not issued a statement on the root cause.
  • The incident follows other major cross-chain bridge exploits in 2026, including losses at Kelp DAO's LayerZero bridge of approximately 116,500 rsETH valued at roughly $292 million.
AFX Bridge Exploit Drains $24.15M in USDC, Attacker Converts Stolen Funds to Ethereum

An exploit targeting the cross-chain bridge operated by AFX resulted in the loss of 24.15 million USDC on July 22, 2026. The breach affected infrastructure run by AFX, a sovereign Layer 1 network for decentralized perpetual trading that uses Arbitrum as a deposit entry point through a third-party bridge — not Arbitrum's native bridge, which continues to operate normally.

Blockchain security firm Blockaid detected the exploit at 21:30 UTC on July 22, 2026, targeting @AFX_XYZ, a protocol on @arbitrum. Arbiscan logs showed the transfer of 24,150,000 USDC from the bridge contract to an attacker-controlled address.

Blockaid stated that its team was working alongside Arbitrum and AFX to assess the situation. As of publication, asset recovery had not occurred, and AFX had not issued a statement regarding the cause of the exploit.

Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol. Our team has been working with the incredible folks on… — Blockaid (@blockaid_) July 22, 2026

Investigation Underway

Steven Goldfeder, co-founder of Offchain Labs, clarified that the suspicious transaction originated from a third-party protocol rather than Arbitrum's native bridge. He confirmed that the team was collaborating with AFX on the investigation and that further details would emerge as it progresses.

According to blockchain security firm PeckShield, the attacker moved the stolen USDC from Arbitrum to Ethereum before converting the proceeds into 12,467.5 ETH. On-chain analytics account Lookonchain reported that the ETH was acquired at an average price of approximately $1,937 per ETH. By converting the proceeds from a stablecoin — whose issuer can freeze balances at the smart-contract level — into a native crypto asset like ETH, the attacker reduced the likelihood of centralized freezing and made the trail harder to interdict.

Cross-Chain Bridge Security Under Renewed Scrutiny

The AFX exploit follows a series of security incidents involving cross-chain bridges in decentralized finance. Bridges have historically been among the most frequently exploited components in DeFi because they custody large pools of locked assets on one chain while issuing corresponding representations on another, creating a concentrated target whose compromise can yield immediate access to substantial funds. Earlier this year, Stake DAO was forced to shut down its vsdCRV bridge following an unauthorized mint on Arbitrum. Separately, Kelp DAO's LayerZero bridge lost approximately 116,500 rsETH, valued at roughly $292 million.

The attack underscores the operational distinction between a blockchain network and the third-party applications built on top of it. In this case, the losses are confined to AFX's bridge infrastructure rather than the Arbitrum network itself. Nevertheless, the incident raises ongoing questions about cross-chain security protocols, bridge authorization mechanisms, and operational procedures governing decentralized bridge systems.