Arbitrum Perp DEX Loses $24 Million Due to Bridge Key Hack


Barely a week after the Ostium oracle exploit arrived at Arbitrum, another event occurred Eternal dicks On the same network it was drained. On July 22, 2026, AFX Trade lost approximately $24.15 million USD after an attacker compromised the validator’s signing keys behind the bridge on which the protocol runs. The stolen funds were transferred to Ethereum and swapped for approximately 12,467 ETH – nearly emptying the total value of the locked exchange.

Once again, the vulnerability was not the smart contract code. It was the off-chain infrastructure around, in this case the bridge managed by AFX itself rather than Arbitrum’s original bridge.

What happened to AFX Trade?

Security company Blockaid reported the exploit at 21:30 UTC on 22 July. The attacker was able to gain control of the validator’s signing keys for AFX’s USDC custodial bridge – the component that allows cross-chain withdrawals. With enough signatures to meet the bridge’s quorum, the malicious withdrawal seemed perfectly legitimate to the system.

These details are important: Blockaid noted that the on-chain logic works exactly as designed. Five authenticated signatures met the minimum required to approve the transfer, so the contract released the funds without any error. The problem was that the keys that produced those signatures were in the wrong hands.

After draining the vault, the attacker transferred USDC from Arbitrum to… Ethereum I exchanged them for about 12,467 ETH at an average of about $1,937 per token. According to PeckShield, the transferred ETH is integrated into a single wallet.

Was the Arbitrum network itself hacked?

No – this distinction is important. The vulnerability affected a third-party bridge maintained by AFX over Arbitrum, not Arbitrum’s native bridge or the broader second layer. Steven Goldfeder, co-founder of Offchain Labs (the team behind Arbitrum), stated that the network’s original bridge had not been hacked or exploited in any way.

A breach of the Arbitrum’s private bridge could have affected the entire Layer 2 ecosystem. By contrast, a compromised application on top of it is a built-in failure — bad for AFX and its users, but not a systemic threat to other Arbitrum protocols.

Why are bridges a common goal?

Bridges have been one of the most profitable attack vectors in… Decentralized finance For years, the reason is structural. They have large pools of locked assets and rely on validation sets or multi-signature arrangements to allow transfers. This concentrates trust in a small set of keys – and if those keys are compromised, the on-chain code will happily approve withdrawals that appear to be properly signed.

The AFX incident fits the pattern neatly. Arbitrum’s trading engine and core infrastructure are untouched; The only weak link was the signature layer of the bridge, which the team ran themselves. It reflects the broader story of 2026, where most of DeFi’s major losses came from compromised off-chain components rather than flawed Solidity.

Want a structured alternative? Browse our list of MiCA licensed exchangesWant a structured alternative? Browse our list of MiCA licensed exchanges

How much did you steal and where is the money now?

About $24.15 million USDC has been drained, which is nearly the total TVL value of the protocol. Unlike many exploits where funds disappear into a mixer, here the trail is still visible: the attacker exchanged USDC for approximately 12,467 ETH and left it in a known Ethereum wallet, with no significant withdrawals reported. Security companies Blockaid and PeckShield are actively tracking the address.

Not laundering money yet leaves a narrow window for recovery – which is exactly what AFX is trying to exploit.

What does AFX do for refunds?

Hours after the attack, AFX suspended the compromised bridge and made a public offer to the attacker: return 70% of the stolen assets and keep the remaining 30% – approximately $7.2 million – as a “white hat bounty.” The team has published a specific Ethereum address for return.

This has become the standard playbook for cryptocurrency exploits. The logic is straightforward: recovering 70% of the money is better than recovering anything, and modern on-chain forensics make it increasingly difficult to launder large sums without eventually being identified. However, it is not without criticism – some security researchers argue that paying attackers normalizes a “steal first, negotiate later” dynamic. The success of the matter here depends entirely on whether the attacker would prefer a clean exit from the risk of trying to move ETH.

To date, the exact way the keys were compromised is still under investigation, and the funds remain in the attacker’s wallet.

advertisement

xtb-nike-share-free

What does the AFX hack mean for DeFi traders?

For anyone using perpetual DEXs on Layer 2 networks, the lesson is to look beneath the trading interface. A protocol can have powerful smart contracts for its Perps engine, and still be invalidated if the bridge it relies on has central verification keys. The two AFX and Ostium incidents in the space of one week – both on Arbitrum, and both off-chain settlements – make this point difficult to ignore.

Practical tips for traders: Understand whether the platform relies on a self-operated bridge, be careful about how much capital you leave parked in one place, and follow official channels rather than threads of rumors during an active incident.

Where can you trade cryptocurrencies on regulated platforms instead?

Incidents like the AFX hack are a reminder of the trade-off that comes with unaudited or poorly regulated venues. In the EU, the MiCA framework now sets a common standard: since 1 July 2026, any platform serving EU clients needs a Crypto Asset Service Provider (CASP) licence, covering governance, client asset protection, IT security, and anti-money laundering requirements. As of late July 2026, the ESMA Register lists approximately 300 CASPs approved across the EEA, with one permit passing through all Member States.

If you prefer to trade on regulated, compliant platforms rather than exposing funds to a bridge or Oracle-based perp DEX, it’s worth comparing venues by licensing status, fees, and available assets. Our broker and exchange comparison page breaks this down so you can choose a platform that actually matches how you trade.

One of the structured options is XTBa publicly listed brokerage firm that has received approval to offer spot cryptocurrency trading to EEA clients (through a Cyprus licence), alongside its own regulated brokerage products. You can open an account with XTP here.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *