Arbitrum Perpetuals Exchange AFX Trade Drained of $24 Million in Bridge Exploit
Key Takeaways
- •AFX Trade lost $24.15 million when its self-operated USDC custody bridge on Arbitrum was exploited, though the exact attack vector remains under investigation.
- •The attacker converted the stolen USDC into 12,468 ETH on Ethereum, with the funds currently sitting in a single wallet.
- •Arbitrum's native bridge was not compromised, and AFX confirmed the damage was isolated to its own custody bridge without affecting trading infrastructure or the broader network.
- •AFX's head of growth publicly offered the attacker a white hat deal to return 70% of the stolen funds and keep the remaining 30% as a bounty.
- •The theft contributes to more than $840 million in DeFi hack losses in 2026 and marks the second major exploit of an Arbitrum-based perpetuals exchange in one week, following Ostium's $18 million loss.

AFX Trade, a decentralized perpetuals exchange built on Arbitrum that settles in USDC, was drained of $24.15 million on Wednesday in an exploit targeting a USDC custody bridge operated by the protocol itself, according to security firm Blockaid.
The exchange confirmed the incident and said the exact attack vector remains under investigation. On-chain analytics firm PeckShield reported that the attacker bridged the stolen USDC to Ethereum and swapped it for 12,468 ETH, which is currently held in a single wallet. The transaction can be viewed on Arbiscan.
Cross-chain bridges have consistently ranked among the most targeted components in decentralized finance, since they pool large volumes of assets under custodial or smart-contract control to facilitate transfers between networks. Major bridge exploits include the $625 million Ronin Network breach in 2022 and the $326 million Wormhole attack the same year.
AFX issued a public statement on X:
AFX is aware of an incident involving the AFX-operated USDC custody bridge on Arbitrum. Upon detecting the incident, we immediately suspended bridge operations and initiated our incident response procedures. Our engineering and security teams are actively investigating the root…
— AFX Trade (@AFX_XYZ) July 23, 2026
Arbitrum co-founder Steven Goldfeder moved quickly to distance the layer-2 network from the incident, stating that Arbitrum's native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol. A breach of Arbitrum's own bridge would have far-reaching consequences across the entire layer-2 ecosystem, whereas a compromised application on top of it represents a contained failure.
AFX echoed that assessment, saying the damage appeared "isolated to the AFX-operated custody bridge." The exchange noted that neither its trading infrastructure and mainnet, nor the Arbitrum network itself, had been compromised. The firm added that it was collaborating with ecosystem partners and security firms to trace the stolen assets.
Hours later, AFX's head of growth, Ken C, publicly offered the attacker a deal: return 70% of the stolen funds and keep the remaining 30% as a "white hat bounty." Such appeals have become a recurring tactic in crypto exploits, in part because once stolen assets are converted to ETH and held in a self-custodied wallet, recovery through legal or technical means is extremely limited. In April, Solana-based Drift Protocol made a similar overture following its $285 million hack.
The theft adds to an already damaging year for DeFi, which has lost more than $840 million to hacks in 2026. The incident also comes just one week after fellow Arbitrum perpetuals venue Ostium was drained of $18 million through a compromised oracle key, underscoring the particular exposure of leveraged trading protocols on Arbitrum to infrastructure-level attacks.