AFX Trade Hit by $24.15M Bridge Exploit, Offers Attacker 30% to Return Funds

AI Market Summary
AFX Trade's $24.15M bridge exploit on Arbitrum (via an AFX-operated third-party bridge, not Arbitrum's native bridge) adds to July 2026 hack losses nearing $97M and reinforces persistent bridge-key and validator centralization risks in DeFi. Stolen USDC was bridged to Ethereum and swapped into ~12,467 ETH, creating direct flow-related sensitivity in ETH and worsening risk appetite across L2/DeFi venues.
Impact level
● Medium
Affected assets
ETH/USDT-1.16%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
AFX Trade, a decentralized perpetuals exchange on Arbitrum, suffered a $24.15 million loss on July 22 after an attacker compromised validator signing keys tied to the platform's bridge. The hacker drained USDC from the protocol, bridged the funds to Ethereum, then swapped them into about 12,467 ETH at an average price near $1,937 per ETH. AFX Trade responded by publicly offering the attacker a deal: keep 30% of the stolen funds (about $7.2 million) if the remaining 70% is returned. The breach did not involve Arbitrum's native bridge infrastructure. According to the details shared, the attack targeted a third-party bridge operated by AFX Trade. Arbitrum itself was not compromised, and its core bridging mechanism remains intact. The vulnerability was in the additional layer AFX maintained, where access to validator signing keys effectively allowed unrestricted fund movement. The incident mirrors a familiar bridge-exploit pattern. A comparable method was used in the May 2026 attack on the Verus–Ethereum bridge. Security firm Blockaid grouped the AFX Trade incident into a broader cluster it labeled "Hackers Day," and said total hack losses in July 2026 have climbed to nearly $97 million. Offering a "30% bounty" to recover funds has become a common playbook in crypto exploits, reflecting the view that recovering 70% is preferable to a total loss and that on-chain traces can make large-scale laundering increasingly difficult. Bridge attacks continue to rank among the most profitable vectors in DeFi because bridges often custody large pools of locked assets and depend on validator sets or multisig designs that create concentrated points of failure. In this case, the weak link was a protocol-maintained third-party bridge rather than the underlying Layer 2 network. For investors and traders using perpetual DEXs on Layer 2 networks, the episode underscores the need to scrutinize the plumbing behind the interface. Even if the perps engine is sound, reliance on a bridge with centralized validator keys can turn into a single point of failure if those keys are compromised.