Security experts reported that the attacker leveraged sufficient hot-validator signatures to facilitate a withdrawal of 24.15 million USDC, while Arbitrum stated that its primary bridge remained secure.
By Shaurya MalwaUpdated Jul 23, 2026, 5:16 a.m. Published Jul 23, 2026, 5:01 a.m. 2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on AFX Trade on Arbitrum loses $24 million due to compromised bridge keys. (Kevin Ku/Unsplash)SummaryShow- AFX Trade, a decentralized exchange for perpetual contracts on Arbitrum that uses USDC for settlements, lost approximately $24.15 million when a hacker gained access to the validator signing keys for a bridge used by the protocol.
- Arbitrum confirmed that its own bridge was not compromised, and Blockaid indicated that the on-chain logic operated as intended, with five hot-validator signatures validating the withdrawal.
- The stolen USDC was transferred to Ethereum and converted into around 12,467 ETH, significantly depleting AFX’s total value locked during a troubling period of notable crypto hacks targeting Arbitrum protocols.
In yet another multi-million-dollar security breach in the DeFi sector, this incident highlights an off-chain vulnerability rather than a flaw in smart contracts.
AFX Trade, which is a decentralized perpetuals exchange that settles transactions in the stablecoin USDC, experienced a theft of about $24.15 million on Wednesday after an attacker exploited the validator signing keys associated with a bridge the protocol utilizes on Arbitrum, as detailed by blockchain records.
The smart contract functioned correctly by validating the signature and processing the transaction. The critical failure was tied to the private keys that were responsible for creating those signatures, which the attackers managed to compromise (the hot keys are maintained off-chain by bridge operators or validators).
Steven Goldfeder, co-founder of Offchain Labs, which oversees the network, stated that the Arbitrum native bridge "has not been hacked or exploited in any way" and clarified that the transaction came from a third-party protocol.
If Arbitrum's own bridge had been hacked, it would indicate a broader risk to the entire layer-2 network; however, the breach of a protocol built on top of it is a more contained issue.
Importantly, there were no flaws in the bridge's coding logic. Bridges are blockchain mechanisms that facilitate the transfer of tokens across different networks, including those not initially supported.
According to Blockaid, the on-chain logic was not circumvented; instead, the five hot-validator signatures required to authorize the withdrawal collectively permitted the transfer of 24,150,000 USDC to the hacker's wallet, achieving the necessary two-thirds quorum.
This scenario bears resemblance to the approximately $285 million loss suffered by Drift Protocol in April, where attackers took months to gain privileged access instead of exploiting any contract vulnerabilities.
This incident comes at a time when the crypto space is facing significant security challenges, with Q2 being one of the worst quarters for recorded hacks, alongside a series of attacks on Arbitrum-based protocols, including a separate exploit that drained $18 million from the RWA platform Ostium just a week earlier, occurring in rapid succession.
Most of this year's hacks and exploits have focused on off-chain components rather than vulnerabilities inherent in smart contracts.
Blockaid identified an exploit on 2026-07-22 21:30 UTC that targeted @AFX_XYZ, a protocol on @arbitrum. The exploit specifically involved a bridge operated by AFX. Around 24.15M USDC has been drained from the protocol to date.
— Blockaid (@blockaid_) July 22, 2026
Our team has been collaborating with the dedicated individuals on… https://t.co/0Qd9ve5gPB
The contract processed the withdrawal as legitimate and dispensed the funds after a 200-second dispute period. While the bridge functioned as intended, the keys that enabled the withdrawal were evidently compromised.
The attacker subsequently bridged the stolen USDC to Ethereum and traded it for approximately 12,467 ETH, valued at around $24 million, which on-chain monitors now indicate remains in a single wallet.
In the lead-up to the attack, AFX's trading volume had surged, with daily perpetuals volume reaching multi-month highs in mid-July, as noted by DefiLlama, attracting more users and deposits.
The nearly $24 million siphoned off represented almost the entire value locked within the protocol, indicating the attacker struck when the vault was near its fullest.