NewsCryptoAFX Trade Loses $24.15 Million in Arbitrum Bridge Exploit

AFX Trade Loses $24.15 Million in Arbitrum Bridge Exploit

Author: AMBCrypto·

Key Takeaways

  • AFX Trade lost approximately $24.15 million in USDC after a security breach affected its Arbitrum bridge.
  • The attacker transferred the stolen assets to Ethereum and converted them into 12,467.44 ETH worth about $24.16 million at the time.
  • SlowMist reported that the stolen funds remain in the attacker's Ethereum wallet, which has been made public for monitoring.
  • AFX Trade suspended activity on the compromised bridge, activated its incident response process, and offered a white hat settlement to the attacker.
  • The breach involved external bridge infrastructure connected to Arbitrum, not Arbitrum's native bridge.
AFX Trade Loses $24.15 Million in Arbitrum Bridge Exploit

AFX Trade, a decentralized exchange offering cryptocurrency and stock perpetuals, has suffered a security breach on its Arbitrum bridge, resulting in the loss of approximately $24.15 million in USD Coin (USDC). Cross-chain bridges, which enable assets to move between separate blockchain networks like Ethereum and its Layer-2 scaling solution Arbitrum, have consistently ranked among the most targeted categories of decentralized finance infrastructure.

According to details of the incident, the attacker transferred the stolen funds from the Arbitrum (ARB) network to Ethereum (ETH), moving the assets beyond their original chain and complicating recovery efforts. The attacker then converted the USDC into 12,467.44 ETH, valued at approximately $24.16 million at the time. By swapping the stablecoin for ETH, the hacker obtained a more liquid and portable asset.

After consolidating the stolen funds into a single Ethereum wallet, no further large withdrawals were observed. The attacker's Ethereum wallet address has since been made public, enabling blockchain analysts and investigators to monitor any potential movement of the assets.

AFX Isolates Breach to Custody Bridge

AFX Trade traced the source of the compromised funds to an individual Ethereum account. Following the discovery, the exchange suspended all activity on the affected bridge and activated its incident response protocol. The platform is working alongside blockchain security partners to track any additional movement of the stolen tokens.

Blockchain security firm SlowMist reported that the stolen funds remain in the attacker's wallet. This allows the Crypto Defense Alliance (CDA) and multiple exchanges to coordinate monitoring of future transactions.

Zellic, the firm that previously conducted a security audit of the bridge's code, has joined the investigation to review the attack vector. The fact that an audited bridge was still exploited reflects the broader reality that security reviews reduce but do not eliminate risk, particularly when post-audit code changes or operational components fall outside the audit scope. AFX Trade has also extended a white hat settlement offer to the attacker while continuing to trace the assets and release verified updates.

Bridge Attacks Highlight Persistent Cross-Chain Risks

The AFX Trade exploit underscores a recurring pattern of vulnerabilities associated with third-party bridge infrastructure. Arbitrum's native bridge itself was not compromised; rather, the attack occurred through external bridge architecture connected to the network.

Similar incidents involving Ostium and Allbridge Core demonstrate that attackers continue to target cross-chain protocols, highlighting the need for enhanced security measures across bridge infrastructure rather than the underlying blockchain networks themselves. As cross-chain connectivity expands, the recurring nature of these exploits points to systemic challenges in securing third-party bridge systems.