AFX Trade, a decentralized perpetuals exchange that settles in dollar-pegged stablecoin $USDC, was drained of about $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol operates on Arbitrum, blockchain data shows.
Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said the Arbitrum native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol.
A hack of Arbitrum's own bridge would signal risk across the entire layer-2 network, but a compromised protocol running on top of it is a contained failure.
Nothing in the bridge's own code logic was broken. Bridges are a blockchain-based tool to transfer tokens between various networks, including ones they were not initially supported on.
Security firm Blockaid said the on-chain logic was not bypassed. Instead, five of the bridge's hot-validator signatures, the approvals that authorize a withdrawal, signed off on moving 24,150,000 $USDC to the attacker's wallet, clearing the roughly two-thirds quorum the bridge requires.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M $USDC has been drained thus far from the protocol.
— Blockaid (@blockaid_) July 22, 2026
Our team has been working with the incredible folks on… https://t.co/0Qd9ve5gPB
The contract treated the withdrawal as valid and released the funds after a 200-second dispute period. The bridge did exactly what it was designed to do, but the keys authorizing were apparently in the wrong hands.
The attacker then bridged the stolen $USDC to Ethereum and swapped it for about 12,467 ETH, worth roughly $24 million, which on-chain trackers say now sits in a single wallet.
AFX's trading activity had been climbing sharply in the run-up to the attack, with daily perpetuals volume spiking to multi-month highs in mid-July, according to DefiLlama, as the protocol drew in users and, with them, deposits.
The roughly $24 million drained was almost the entirety of the protocol's total value locked, meaning the attacker emptied the vault at close to the moment it was fullest.
The loss lands amid a punishing stretch for crypto security, with Q2 among the worst quarters for hacks on record and a run of Arbitrum-based protocols, including the oracle exploit that drained a separate $18 million from RWA platform Ostium a week earlier, hit in quick succession.
As such, the incident is a similar failure to the roughly $285 million Drift Protocol loss in April, where attackers spent months working their way to privileged access rather than breaking any contract.