AFX Trade Hack: Arbitrum Perp DEX Loses $24M as Bridge Keys Are Compromised
AFX Trade lost $24.15M USDC after attackers compromised its bridge validator keys. The perp DEX offered the hacker a 30% bounty to return it.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Barely a week after the Ostium oracle exploit hit Arbitrum, another perpetuals DEX on the same network was drained. On July 22, 2026, AFX Trade lost roughly $24.15 million USDC after an attacker compromised the validator signing keys behind a bridge the protocol operates. The stolen funds were moved to Ethereum and swapped for around 12,467 ETH — nearly emptying the platform's total value locked.
Once again, the weak point wasn't the smart contract code. It was the off-chain infrastructure sitting around it, and in this case a bridge that AFX ran itself rather than Arbitrum's native one.
What happened to AFX Trade?
Security firm Blockaid flagged the exploit at 21:30 UTC on July 22. The attacker gained control of the validator signing keys for AFX's USDC custody bridge — the component that authorizes cross-chain withdrawals. With enough signatures to meet the bridge's quorum, the malicious withdrawal looked entirely legitimate to the system.
That detail matters: Blockaid noted the on-chain logic worked exactly as designed. Five hot-validator signatures met the threshold needed to approve the transfer, so the contract released the funds without any bug being triggered. The problem was that the keys producing those signatures were in the wrong hands.
After draining the vault, the attacker bridged the USDC from Arbitrum to Ethereum and swapped it for roughly 12,467 ETH at an average of around $1,937 per token. According to PeckShield, the converted ETH was consolidated into a single wallet.
Was the Arbitrum network itself hacked?
No — and that distinction is important. The exploit hit a third-party bridge that AFX maintains on top of Arbitrum, not Arbitrum's native bridge or the wider Layer 2. Steven Goldfeder, co-founder of Offchain Labs (the team behind Arbitrum), stated the network's native bridge had not been hacked or exploited in any way.
A breach of Arbitrum's own bridge would have rippled across the entire Layer 2 ecosystem. A compromised app sitting on top of it, by contrast, is a contained failure — bad for AFX and its users, but not a systemic threat to other Arbitrum protocols.
Why are bridges such a common target?
Bridges have been one of the most lucrative attack vectors in DeFi for years, and the reason is structural. They hold large pools of locked assets and depend on validator sets or multisig arrangements to authorize transfers. That concentrates trust in a small set of keys — and if those keys are compromised, the on-chain code will happily approve withdrawals that look properly signed.
The AFX incident fits the pattern precisely. The trading engine and Arbitrum's core infrastructure were untouched; the single weak link was the signing layer of a bridge the team operated itself. It echoes the broader story of 2026, in which most major DeFi losses have come from compromised off-chain components rather than flawed Solidity.
How much was stolen, and where is the money now?
Around $24.15 million in USDC was drained — close to the protocol's entire TVL. Unlike many exploits where funds vanish into a mixer, here the trail is still visible: the attacker swapped the USDC for roughly 12,467 ETH and left it sitting in a known Ethereum wallet, with no large follow-on withdrawals reported. Security firms Blockaid and PeckShield are actively tracing the address.
That the funds haven't been laundered yet leaves a narrow window for recovery — which is exactly what AFX is trying to exploit.
What is AFX doing to recover the funds?
Hours after the attack, AFX suspended the compromised bridge and made a public offer to the attacker: return 70% of the stolen assets and keep the remaining 30% — roughly $7.2 million — as a "white hat bounty." The team posted a specific Ethereum address for the return.
This has become a standard playbook in crypto exploits. The logic is blunt: recovering 70% beats recovering nothing, and modern on-chain forensics make laundering a large sum increasingly hard without eventually being identified. It's not without critics, though — some security researchers argue that paying attackers normalizes a "steal first, negotiate later" dynamic. Whether it works here depends entirely on whether the attacker prefers a clean exit to the risk of trying to move the ETH.
As of now, the exact method by which the keys were compromised is still under investigation, and the funds remain in the attacker's wallet.
What does the AFX hack mean for DeFi traders?
For anyone using perpetual DEXs on Layer 2 networks, the lesson is to look underneath the trading interface. A protocol can have solid smart contracts for its perps engine and still be gutted if the bridge it relies on has centralized validator keys. The AFX and Ostium incidents within a single week — both on Arbitrum, both off-chain compromises — make that point hard to ignore.
Practical takeaways for traders: understand whether a platform relies on a self-operated bridge, be cautious about how much capital you leave parked in one venue, and follow official channels rather than rumor threads during an active incident.
Where can you trade crypto on regulated platforms instead?
Incidents like the AFX hack are a reminder of the trade-off that comes with unaudited or lightly regulated venues. In the EU, the MiCA framework now sets a common standard: since July 1, 2026, any platform serving EU clients needs a Crypto-Asset Service Provider (CASP) authorization, covering governance, client-asset safeguarding, IT security, and AML requirements. As of late July 2026, the ESMA register lists close to 300 authorized CASPs across the EEA, with a single authorization passporting across all member states.
If you'd rather trade on regulated, compliant platforms than expose funds to a bridge or oracle-dependent perp DEX, it's worth comparing venues by their license status, fees, and available assets. Our broker and exchange comparison page breaks this down side by side so you can pick a platform that matches how you actually trade.
One regulated option is XTB, a publicly listed, established broker that has secured approval to offer spot crypto trading to EEA clients (via its Cyprus authorization), alongside its regulated brokerage products. You can open an account with XTB here.
Related articles
- $42 Million in Eight Days: Why ‘Decentralised’ Stopped Protecting Perp DEX Traders
- Ostium Hack: Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23
- DeFi Hack: Aave and LayerZero Hit by Sophisticated DPRK Attack
- Velocity Replaces Drift After the 285 Million Dollar Hack: What Changes for Investors in Germany
- Ajna Exploit: $775,400 Drained and No Pause Button in the DeFi Lending Protocol
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
May 23, 2025 6:49 PM

Cetus Hack on Sui Network: What Happened and Why SUI Price Is Crashing
A $260 million exploit on Sui’s top DEX, Cetus Protocol, has triggered panic across the ecosystem. Here's what really happened, how Sui is responding, and what it means for the SUI token price.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
September 23, 2026 4:10 PM

Fetch.ai Bridge Exploit: What FET, AGIX and NTX Holders Must Check Now
A single call drained the FET liquidity of the SingularityNET bridge on September 19, and hundreds of millions of unbacked tokens were minted afterwards. What is affected, what Fetch.ai has halted, and what to check in your wallet, at your exchange and on tax.
September 13, 2026 4:13 AM

Symbiosis Hack: How to Check Whether Your Bridged Bitcoin Can Still Get Out
An attacker minted billions of unbacked syBTC on the cross-chain bridge Symbiosis and pulled out roughly $336,000. We checked for ourselves on September 12 which routes are still running: the way into the bridge is suspended, the way out is open.
May 12, 2025 9:05 PM

US-EU Trade Tensions Rise as US-China Conflict Cools Down
Just as the long-standing US-China trade war appears to ease, new tensions are emerging between the United States and the European Union. With Trump calling Europe “nastier than China,” are we about to witness a new transatlantic trade conflict?
August 22, 2026 10:39 AM

Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
On August 18, 2026 an attacker drew roughly $1.65 million out of MAYAChain's liquidity pools through six chained faults, and the team then halted the chain globally. Anyone who swapped or provided liquidity there can check in a few minutes whether their own money is stuck in the halted system.
April 21, 2026 2:00 PM

LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
A $292M exploit on KelpDAO exposes a massive LayerZero vulnerability. With 47% of apps at risk, are your assets still safe in the crypto space?
September 7, 2026 11:06 AM

Liquid Network Hack: $320 Million In Bitcoin Walked Out, And The Hacker Wants To Give It Back
Nearly 4,000 BTC left Liquid Network's federation wallet. The attacker says he is a white hat and is negotiating with Blockstream on-chain.
June 17, 2024 10:59 AM

TOP 3 DEX for June 2024
What are the best DEXs to use in 2024? Here are the top 3 for June 2024!
September 28, 2026 1:15 PM

Arbitrum One in Practice: What Matters for Bridge, Gas and the Seven-Day Wait
A transfer on Arbitrum One cost around a tenth of a cent today, while the way back to Ethereum takes at least seven days. This guide shows how to set up the network, read Arbiscan and revoke approvals — and why the Security Council is part of the picture.
November 27, 2024 7:01 PM

Uniswap Bug Bounty: The 'Largest Bug Bounty in History' ahead of v4 Core Contracts Release
Uniswap Labs has launched the largest bug bounty in crypto history, a groundbreaking $15.5 million bug bounty program to secure its upcoming v4 core contracts. Full details here...
August 23, 2026 10:14 PM

Term Finance Governance Exploit: Why Audited Code Does Not Protect Your DeFi Deposits
Around $8.5 million flowed out of the Ethereum lending protocol Term Finance on August 23, 2026, after an attacker bought a voting majority over the deposit pools. The code itself stayed intact: here is how to judge how easily a DeFi pool can be opened by a vote.
May 27, 2024 11:56 AM

Wave of Crypto Hacks and Exploits Hits Influencers and Memecoins: WATCH OUT!
A series of hacks on crypto influencers, celebrities, and a major memecoin exploit have raised serious security concerns within the cryptocurrency community. Here is what you need to watch out for!
September 12, 2026 4:49 AM

USDC Bridge CCTP V1 Is Shutting Down: How to Check Whether Your Stablecoin Can Still Change Chain From December
Circle halts the old version of its official USDC bridge on December 1, 2026, and the caps start falling on October 31. Our own count shows which 29 chains already have the successor, which two are left out, and how much USDC still sits on the discontinued chain Noble today.
August 31, 2026 4:12 AM

Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
On August 30, 2026, the validators of the Cronos chain halted block production after an attacker had emptied the lending market Tectonic via an inflated TONIC price. What is established, why the damage figures diverge, and what you can check if your balance sits on a haltable chain.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 25, 2026 1:47 PM

Magic Eden and Limit Break exploit: 530 WETH and thousands of NFTs drained, how to revoke your approvals
A bug in Limit Break's Payment Processor, the protocol behind Magic Eden's former Ethereum marketplace, has been draining NFTs and WETH since Thursday. Our blockchain analysis shows 911 affected wallets. What happened, why hardware wallets do not protect you and which two approvals to revoke now.
August 31, 2026 4:27 PM

More Markets Exploit: How a Liquid Staking Token and E-Mode Pulled $9.3 Million Out of a Lending Market
Around 15.5 million WFLOW drained from the lending market More Markets on August 31, 2026, roughly $9.3 million by Blockaid's estimate. The route ran through a liquid staking token used as collateral and through E-Mode, and both building blocks sit in protocols you know.
August 24, 2026 4:32 AM

LayerZero Drops 15 Chains From August 28: What Stargate Users Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: LayerZero had announced it would end DVN and Executor services for 15 blockchains on August 28, 2026, among them Arbitrum Nova, Cronos zkEVM and Degen. This article describes the situation before the deadline and the routes for moving Stargate-bridged balances to a supported chain.
August 23, 2026 7:24 PM

SAND Bridge Exploit at The Sandbox: Why Not to Trade SAND on Base and BNB Chain Now
An attack on The Sandbox's cross-chain bridge created unbacked SAND tokens on Base and BNB Smart Chain on August 22, 2026. Bridging is halted; holdings on Ethereum and Polygon are unaffected, according to the studio.
June 28, 2026 8:12 PM

Polymarket Hack: $3.1M Stolen as Prediction Market Hype Faces Its Biggest Test
Polymarket hack shocks prediction markets as $3.1M is stolen from 11 wallets. Is the sector ready for mainstream adoption?
April 13, 2026 9:54 AM

Hyperbridge Exploit: Fake Polkadot $DOT Minting Triggers $20M Flash Crash
Polkadot (DOT) price dropped 5% in minutes following a Hyperbridge exploit where an attacker minted 1 billion fake DOT on Ethereum, causing $20M in market cap loss.
October 1, 2026 2:16 PM

Open USD is live but absent from the EU register: what matters now for investors in Europe
The dollar stablecoin Open USD launched on September 30, 2026, backed by Coinbase, Mastercard, Shopify, Stripe and Visa. On October 1, 2026 the token was not notified in the MiCA register, and that decides what you can do with it in Europe.
September 30, 2026 10:24 PM

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.
September 30, 2026 4:25 PM

Shiba Inu price 4.9 percent below the month high: Why SHIB is falling
Shiba Inu trades at $0.00000581 on Wednesday afternoon, 4.9 percent below the high of September 23, even though the coin is up 17.0 percent over 30 days. The reasons are not in the chart but in the network data and in the cost structure of trading.
September 26, 2026 1:11 AM

Funding Rate on Perpetual Futures: How to Calculate What Your Position Really Costs
A rate of 0.01 percent per interval sounds like nothing and works out at almost 11 percent of the notional value over a year. This guide walks through the calculation, the timestamp effect and the way leverage multiplies the burden.
September 21, 2026 4:24 PM

Jupiter Rises: Money Is Rotating Back Into Solana DeFi
Solana gains 7.6 percent, the trading aggregator Jupiter 13 percent. When applications rise faster than the chain, capital is looking for leverage inside the ecosystem. What sits behind it and where the risk lies.
More from CryptoTicker


