Arbitrum-Based AFX Trade Drained of $24 Million After Bridge Keys Compromised
Key Takeaways
- •The attacker used compromised validator signing keys to authorize a 24.15 million USDC withdrawal from AFX Trade’s bridge.
- •Blockaid said the exploit did not bypass on-chain logic, as the contract verified valid signatures and executed as designed.
- •The stolen funds were moved to Ethereum and swapped for approximately 12,467 ETH, worth about $24 million.
- •Offchain Labs co-founder Steven Goldfeder said Arbitrum’s native bridge was not hacked or exploited.
- •The loss represented nearly all of AFX’s total value locked after a recent rise in trading activity and deposits.

AFX Trade, a decentralized perpetuals exchange built on Arbitrum that settles in dollar-pegged USDC, was drained of approximately $24.15 million on Wednesday after an attacker compromised the validator signing keys powering a bridge the protocol operates, blockchain data shows.
The incident is the latest in a string of high-profile exploits targeting off-chain components rather than smart contract vulnerabilities. In this case, the on-chain logic performed exactly as designed — it verified signatures and executed the transaction. The failure lay with the private keys that generated those signatures.
Security firm Blockaid detected the exploit at 2026-07-22 21:30 UTC, targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC was drained from the protocol.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol. Our team has been working with the incredible folks on… — Blockaid (@blockaid_) July 22, 2026
How the Attack Unfolded
The bridge required roughly a two-thirds quorum of validator signatures to authorize a withdrawal. The attacker obtained enough private validator signing keys — the hot keys held off-chain by bridge operators — to produce five valid hot-validator signatures, clearing the threshold needed to approve the movement of 24,150,000 USDC to the attacker's wallet.
The contract treated the withdrawal as legitimate and released the funds after a 200-second dispute period. That window left virtually no time for manual intervention or an emergency pause. Blockaid confirmed that the on-chain logic was not bypassed; the bridge functioned exactly as designed, but the keys authorizing the withdrawal were in the wrong hands.
The attacker then bridged the stolen USDC to Ethereum and swapped it for approximately 12,467 ETH, worth roughly $24 million, which on-chain trackers report now sits in a single wallet. The conversion to ETH is notable because USDC issuer Circle has previously frozen stolen tokens at the contract level in other incidents, a remedy unavailable once funds are held as native ETH.
On-chain transaction data confirms the movement of funds.
Arbitrum's Native Bridge Unaffected
Steven Goldfeder, co-founder of Offchain Labs — the company that develops and maintains Arbitrum — stated that the network's native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol.
A breach of Arbitrum's own bridge would have signaled systemic risk across the entire layer-2 network. A compromised protocol running on top of it, however, represents a contained failure. Bridges are blockchain-based tools for transferring tokens between networks that do not natively support them.
Timing and Context
The timing was particularly damaging for AFX. The protocol's trading activity had been climbing sharply in the run-up to the attack, with daily perpetuals volume spiking to multi-month highs in mid-July, according to DefiLlama, as the platform drew in new users and, with them, deposits. The roughly $24 million drained represented almost the entirety of AFX's total value locked — meaning the attacker emptied the vault at close to the moment it was fullest.
The incident bears similarities to the roughly $285 million Drift Protocol loss in April, where attackers spent months cultivating privileged access rather than breaking any smart contract. Both cases underscore that as audited smart contracts become harder to crack, adversaries are shifting effort toward operational security weaknesses — key management, oracle manipulation, and social engineering of privileged insiders.
The loss comes amid a punishing stretch for crypto security. Q2 2026 ranked among the worst quarters for hacks on record, according to Hacken's Q2 security report, and a cluster of Arbitrum-based protocols has been hit in quick succession. Just one week earlier, an oracle exploit drained a separate $18 million from RWA platform Ostium. Most hacks and exploits this year have targeted off-chain components rather than vulnerabilities in smart contracts themselves.