Crypto news

23.07.2026
09:23

AFX Trade Bridge on Arbitrum Hacked: 24.15 Million USDC Withdrawn, Bridge Suspended

hack

The AFX Trade platform, specializing in perpetual futures trading, has encountered a serious security incident. On July 22, 2026, at 21:30 UTC, 24,150,000 USDC was withdrawn from the AFX bridge, which handles deposits on the Arbitrum network. The project team immediately suspended the bridge's operation and initiated an investigation, involving external cybersecurity experts.

It is important to emphasize: the infrastructure of the AFX trading platform itself, its first-layer mainnet, and the Arbitrum network remained untouched. The attack was directed solely at the custodial bridge used for user deposits. According to on-chain analysts from Blockaid, the withdrawn USDC was converted into Ethereum: the funds were exchanged for approximately 12,467 ETH at an average price of around $1,937. As of the latest update, according to SlowMist, the stolen assets were still located at the attacker's address. This data has already been shared with the Crypto Defense Alliance (CDA), a coalition of exchanges and industry participants coordinating responses to such threats. The company Zellic, which previously conducted an audit of the bridge's code, has also joined the investigation.

Attack Mechanism: Validator Signatures Under Suspicion

The key question is how exactly the hacker managed to gain control of the funds. Analysts at CoinDesk, citing data from Blockaid, indicate that the bridge's smart contract logic was not bypassed. Withdrawing the funds required five validator signatures, which was enough to reach a quorum (approximately two-thirds of the total). After the standard 200-second challenge period, the contract recognized the request as valid and released the funds. This suggests that the attack targeted the compromise of the validators' hot keys, rather than a vulnerability in the code.

Offchain Labs co-founder Steven Goldfeder confirmed that the native Arbitrum bridge was not hacked—the transaction originated from a third-party protocol. AFX has not yet confirmed this mechanism but continues its investigation. Notably, AFX's growth lead under the pseudonym Supercube has already made a "white hat" offer to the attacker: return 70% of the stolen assets and keep 30% as a reward. This offer is valid for a limited time.

My Expert Analysis: This incident is yet another reminder that multi-signature bridges remain one of the most vulnerable points in DeFi infrastructure. The attack on validator keys, rather than smart contracts, shows that even with flawless code, system security can be reduced to zero due to human factors or poor key management practices. Given that in the second quarter of 2026, the crypto industry set an anti-record for the number of attacks (83 incidents with damages of $755.3 million), projects need to fundamentally rethink their procedures for storing and managing hot keys. Currently, AFX has no clear plan for compensating users, adding uncertainty for fund holders.