Hooded figure viewed from behind sitting at multiple monitors showing code and a world map
TECHNOLOGY

AFX Trade Loses $24 Million After Attacker Compromises Bridge Validator Keys

Image Credit: Shutterstock

Key Takeaways

  • An attacker compromised five hot-validator signing keys to clear the bridge’s quorum and authorize a withdrawal of 24.15 million USDC, while the smart contract and Arbitrum’s native bridge functioned as designed.
  • The stolen funds were bridged to Ethereum and swapped for about 12,467 ETH, roughly matching the protocol’s total value locked.
  • The breach follows a pattern of offchain compromises this year, including a $285 million loss at Drift Protocol and an $18 million oracle exploit at Ostium.

AFX Trade, a decentralized perpetuals exchange that settles in USDC, was drained of about $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol operates on Arbitrum, according to on-chain transaction data.

The smart contract underlying the bridge functioned as designed, verifying signatures and executing the withdrawal it was asked to process. The breach instead involved the private validator signing keys, held off-chain by the bridge’s operators, which the attacker used to authorize the transfer.

Arbitrum’s Native Bridge Was Not Involved

Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the Arbitrum network, said in a post on X that Arbitrum’s native bridge “has not been hacked or exploited in any way” and that the transaction originated from a third-party protocol operating on top of the network. Goldfeder said the distinction matters because Arbitrum’s own infrastructure was not involved.

Security firm Blockaid said the bridge’s on-chain logic was not bypassed. Instead, five of the bridge’s hot-validator signatures, the approvals required to authorize a withdrawal, signed off on moving 24,150,000 USDC to the attacker’s wallet, clearing the roughly two-thirds quorum the bridge requires to process a transaction. The contract treated the withdrawal as valid and released the funds after a 200-second dispute period had passed.

Stolen Funds Moved To Ethereum

The attacker bridged the stolen USDC to Ethereum and swapped it for approximately 12,467 ETH, worth roughly $24 million, which on-chain trackers say now sits in a single wallet. The swap converted the stolen funds into a different asset shortly after the theft, a common step attackers take to complicate tracing and recovery efforts.

AFX’s trading activity had been climbing sharply in the weeks before the attack, with daily perpetuals volume reaching multi-month highs in mid-July, according to data from DefiLlama. The roughly $24 million drained represented almost the entirety of the protocol’s total value locked.

Part Of A Wider Pattern Of Offchain Compromises

The incident resembles the pattern seen in an approximately $285 million loss at Drift Protocol in April, in which attackers spent months working toward privileged access rather than exploiting a flaw in the smart contract itself. In both cases, the underlying contract code performed exactly as written; the vulnerability sat instead in how access to sign transactions was controlled and protected.

The loss adds to a difficult stretch for crypto security broadly. Security firm Hacken’s research identified the second quarter of 2026 as among the worst quarters for crypto hacks on record. Arbitrum-based protocols in particular have faced a rapid succession of incidents, including an $18 million oracle exploit that hit the RWA platform Ostium roughly a week earlier.

Most of this year’s major incidents have stemmed from compromises of off-chain components, such as validator keys, oracle feeds, or operator infrastructure, rather than flaws in the smart contracts that execute on-chain logic.

AFX Trade has not yet released a public statement detailing its response to the incident or outlining a plan for affected users.

Blockaid said it detected the exploit at 21:30 UTC on Tuesday and began working with the protocol’s team shortly after, though the firm has not yet published a full postmortem detailing how the validator keys were compromised. Without that additional detail, it remains unclear whether the breach resulted from a phishing attack, a leaked credential, or a more direct compromise of the infrastructure holding the signing keys. That distinction could matter for other protocols assessing their own exposure to similar attacks.

More For You

Explore More News