Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised
Security firms said the attacker used enough hot-validator signatures to approve a 24.15 million USDC withdrawal, while Arbitrum said its native bridge was not affected.
Updated Jul 23, 2026, 5:16 a.m. Published Jul 23, 2026, 5:01 a.m.
Share this article

Summary
Another week, another multi-million-dollar hack in DeFi, and once again, it’s an off-chain compromise rather than a smart contract exploit.
AFX Trade, a decentralized perpetuals exchange that settles in dollar-pegged stablecoin USDC, was drained of about $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol operates on Arbitrum, blockchain data shows.
In other words, the smart contract did what it’s supposed to do – verify the signature and execute the transaction. The problem was with the private keys that generated those signatures, as attackers compromised the private validator signing keys (hot keys held offchain by the bridge operators or validators).
Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said the Arbitrum native bridge “has not been hacked or exploited in any way” and that the transaction originated from a third-party protocol.
A hack of Arbitrum’s own bridge would signal risk across the entire layer-2 network, but a compromised protocol running on top of it is a contained failure.
Nothing in the bridge’s own code logic was broken. Bridges are blockchain-based tools for transferring tokens between various networks, including those they were not initially supported on.
Security firm Blockaid said the on-chain logic was not bypassed. Instead, five of the bridge’s hot-validator signatures, the approvals that authorize a withdrawal, signed off on moving 24,150,000 USDC to the attacker’s wallet, clearing the roughly two-thirds quorum the bridge requires.
This incident, therefore, is similar to the roughly $285 million Drift Protocol loss in April, where attackers spent months working their way to privileged access rather than breaking any contract.
The loss lands amid a punishing stretch for crypto security, with Q2 among the worst quarters for hacks on record and a run of Arbitrum-based protocols, including the oracle exploit that drained a separate $18 million from RWA platform Ostium a week earlier, hit in quick succession.
Most of the hacks and exploits this year have targeted offchain components rather than vulnerabilities in smart contracts themselves.
The contract treated the withdrawal as valid and released the funds after a 200-second dispute period. The bridge did exactly what it was designed to do, but the keys authorizing the withdrawal were apparently in the wrong hands.
The attacker then bridged the stolen USDC to Ethereum and swapped it for about 12,467 ETH, worth roughly $24 million, which on-chain trackers say now sits in a single wallet.
AFX’s trading activity had been climbing sharply in the run-up to the attack, with daily perpetuals volume spiking to multi-month highs in mid-July, according to DefiLlama, as the protocol drew in users and, with them, deposits.
The roughly $24 million drained was almost the entirety of the protocol’s total value locked, meaning the attacker emptied the vault at close to the moment it was fullest.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.
15 hours ago
Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.
Why it matters:
Markets repositioned since June, but Binance held share (~55% user funds, ~24% spot) and drew net inflows in early July while the tracked market saw outflows.


