
AFX Trade, a derivatives exchange that settles trades in USDC, was exploited for approximately $24.15 million on July 22 after an attacker compromised validator signing keys for a bridge the protocol operates on Arbitrum. According to reports from Blockaid, the security firm detected the exploit at 21:30 UTC on July 22 and began coordinating a response with the Arbitrum team. The exploit specifically targeted AFX's bridge operations, not the Arbitrum network itself, as confirmed by Offchain Labs co-founder Steven Goldfeder. An Arbiscan record shows a successful transfer of 24,150,000 USDC from the bridge contract to the recipient address at 21:30:25 UTC. The AFX bridge contract on Arbitrum held about $24.2 million in USDC before the attack, meaning the exploit drained nearly all of the funds locked in the contract, with deposits having grown from about $19.3 million in mid-June.
Security firm Blockaid revealed that the attacker used five hot-validator signatures to authorize the withdrawal, meeting the two-thirds quorum required by the bridge's on-chain logic. As reported by Blockaid, the contract treated the withdrawal as valid and released the funds after a 200-second dispute period, with the bridge functioning exactly as designed but the keys authorizing the withdrawal apparently in the wrong hands. The attacker emptied the vault at close to the moment it was fullest, as AFX's trading activity had been climbing sharply in the run-up to the attack, with daily perpetuals volume spiking to multi-month highs in mid-July. The roughly $24 million drained was almost the entirety of the protocol's total value locked, representing a similar failure to the $285 million Drift Protocol loss in April where attackers spent months working their way to privileged access.
The attacker moved the stolen USDC from Arbitrum to Ethereum (ETH) following the initial drain, converting the proceeds into 12,467.44 ETH. As reported by AMBCrypto, the funds were swapped into ETH at an average price near $1,937 per ETH. Lookonchain separately reported that the exploiter bought approximately 12,467 ETH after moving the funds from Arbitrum. Blockchain security firm PeckShield traced the converted ETH to a single wallet, 0x6276...ebAC, with the tally reflecting funds drained so far and the figure potentially subject to change as the flow continues to be tracked. The exploiter's address was linked to Arkham onchain analytics platform. According to AMBCrypto, after consolidating all the assets into one Ethereum wallet, there were no subsequent large withdrawals from the attackers' wallet, though the stolen funds still sit in the attacker's wallet as reported by SlowMist.
AFX immediately suspended all activities on the bridge and activated its incident response plan after discovering the loss. As reported by AMBCrypto, the exchange, in collaboration with blockchain security partners, began monitoring for additional movement of the stolen tokens. Zellic, which previously audited the bridge code, has joined the investigation to review the attack vector. AFX has also extended a white hat settlement offer while continuing to trace the assets and publish verified updates. The attacker's Ethereum wallet address is now publicly known, enabling investigators and blockchain analysts to track any potential movement or attempt to transfer these assets. The Crypto Defense Alliance (CDA) and several exchanges are monitoring future movements of the stolen funds.
The AFX breach represents the 14th crypto security incident recorded in July, marking a particularly challenging month for the sector. According to data from DefiLlama, 13 hacks across various protocols in July prior to this incident totaled $72.6 million in losses. The AFX exploit brings the July total to approximately $97 million, already surpassing the $75.32 million in losses from hacks in June and continuing a string of similar cross-chain attacks that have drained protocols through their bridge layers. The case remains developing with no recovery confirmed and no verified technical postmortem explaining how the attacker gained authorization to withdraw the funds. As such, the incident is part of a punishing stretch for crypto security, with Q2 among the worst quarters for hacks on record and a run of Arbitrum-based protocols hit in quick succession.
Offchain Labs co-founder Steven Goldfeder addressed the incident directly, drawing a firm line between AFX's bridge and Arbitrum's core infrastructure. As reported by Offchain Labs, Goldfeder confirmed that "the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way." The investigation now centers on the AFX-operated bridge and the authorization process behind the 24.15 million USDC withdrawal. The Arbitrum network continued operating normally, and no loss was reported from its native bridge infrastructure. Goldfeder stated that "we will coordinate with the third party team and will report more details when we have them." The coming days should reveal whether the protocol can freeze or recover any of the stolen funds.