AFX Trade drained of $24.15M via third-party bridge on Arbitrum

Share

A decentralized perpetuals platform on Arbitrum was drained of $24.15 million in USDC after the private keys of a third-party bridge it operates independently were compromised. The attack, detected on July 22, 2026 around 21:30 UTC, did not target the Arbitrum chain itself nor a smart contract bug: funds were released because the required signature quorum was met with private keys that had fallen into the wrong hands.

🔑 Key takeaways

  • $24.15M in USDC drained from AFX Trade on July 22, 2026 at around 21:30 UTC
  • Five hot validator signatures reached the approval quorum (~2/3 required)
  • Arbitrum’s native bridge was not compromised, per Steven Goldfeder (Offchain Labs)
  • The incident is part of a « Hackers Day » totaling more than $35M in losses within 24 hours
  • The ARB token dropped roughly 4% before stabilizing

Attack mechanics: no bug, but compromised keys

According to security firm Blockaid, which detected the incident, the attack does not stem from any flaw in the smart contract logic. The bridge operated by AFX Trade functioned exactly as designed: five hot validator signatures reached the approval quorum representing roughly two-thirds of the required signatures, the smart contract validated the request, and funds were released after the standard 200-second challenge period. The weak link was not the code — it was the private keys themselves.

Once in control of the USDC, the attacker transferred the funds to Ethereum and swapped them for approximately 12,467 ETH, worth around $24 million at the time of conversion. On-chain trackers indicate these ETH now sit in a single wallet, which simplifies investigators’ work but also limits laundering options without triggering alerts.

A third-party bridge, not Arbitrum’s native one

Steven Goldfeder, co-founder of Offchain Labs (the company behind Arbitrum), was quick to clarify a critical point: Arbitrum’s native bridge was not hacked nor exploited in any way. The transaction originated from a third-party protocol — specifically, the bridge AFX Trade ran independently. The distinction matters greatly for the broader ecosystem, as it prevents unjustified loss of trust in the network’s core infrastructure while pinpointing responsibility on the victim protocol for managing its own keys.

« Arbitrum’s native bridge was not hacked or exploited in any way. The transaction came from a third-party protocol, namely the bridge operated independently by AFX Trade. »

Steven Goldfeder, co-founder of Offchain Labs

The timing makes the incident especially cruel for AFX Trade: the platform had been experiencing strong growth in trading activity in the weeks prior. Daily perpetuals volume hit multi-month highs in mid-July, according to DefiLlama data. The approximately $24.15 million stolen represented nearly the entire total value locked (TVL) of the protocol — the attacker emptied the vault at the very moment it was fullest.

« Hackers Day »: $35M stolen in 24 hours

The AFX Trade incident is not isolated. Security firms PeckShield and Blockaid reported several protocols exploited within the same 24-hour window — an episode dubbed « Hackers Day » by some industry participants. The table below summarizes the main losses recorded:

ProtocolNetworkAsset stolenAmount (USD)
AFX TradeArbitrumUSDC$24.15M
VerusEthereumETH / tokens$7.55M
BSquaredNetworkBNB ChainB2$3.86M
Cumulative total~$35.56M

July 2026 alone accounts for at least 14 crypto security incidents, bringing cumulative losses to roughly $97 million, according to data compiled by security firms. That figure already exceeds the $75.32 million lost over the entirety of June and confirms that Q2 2026 ranks among the worst quarters on record for crypto hacks.

Governance flaws flagged by Taylor Monahan

Beyond the technical mechanics, the attack exposes serious shortcomings in AFX Trade’s governance practices. Taylor Monahan, an on-chain security expert, reviewed a recently published audit of the bridge and delivered a harsh verdict: almost no test coverage, multiple issues flagged by auditors acknowledged but never fixed, and auditors who had only been given portions of the code to examine.

« The details are terrifying. Almost no test coverage, problems acknowledged but never fixed, and the auditors could not even fully examine the code. »

Taylor Monahan, on-chain security expert

According to Monahan, the biggest red flags lie less in the technical vulnerabilities themselves than in what they reveal about the team’s security culture. This attack fits a pattern observed over recent months: the majority of recent hacks and exploits target off-chain components (keys, validators, internal operations) rather than flaws in smart contracts. The Drift protocol incident in April 2026 — where attackers spent months gaining privileged access — illustrates the same dynamic.

On the market side, the ARB token fell roughly 4% in the wake of the announcement before stabilizing. Blockaid posted on X that it had « detected an exploit on 2026-07-22 at 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum, » specifying that the exploitation was specific to the bridge operated by AFX and that the $24.15 million drained constituted, at this stage, the identified amount.


Conclusion: a vault emptied at its peak

The attack on AFX Trade illustrates an uncomfortable truth for DeFi: a protocol can be technically flawless on paper and still be drained of its TVL if key management and operational governance lag behind. The coming weeks will tell whether the AFX Trade team manages to recover part of the funds, negotiate a bounty with the attacker, or whether those $24.15 million will join the growing list of definitive losses from Q2 2026. For users, the lesson is clear: auditing a smart contract is no longer enough — one must also audit the keys, the validators, and the security culture of the team handling them.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice in any form. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles