Crypto

AFX Trade Hit by $24 Million Exploit Targeting Proprietary USDC Bridge

The decentralized perpetuals exchange has halted bridge operations and offered the attacker a 30% bounty to return the stolen assets.

AFX Trade, a decentralized perpetuals exchange operating on the Arbitrum network, has suffered a major security breach resulting in the loss of approximately $24.15 million. The exploit specifically targeted a proprietary custody bridge managed by the protocol to handle USDC stablecoin transactions.

According to blockchain security firm Blockaid, which first flagged the incident, the attacker managed to compromise the bridge’s architecture. On-chain data analyzed by security firm PeckShield reveals that the exploiter quickly converted the stolen USDC into 12,468 ETH. The assets were subsequently transferred to Ethereum mainnet, where they currently remain consolidated in a single wallet address.

In the immediate aftermath of the attack, Arbitrum developers moved to clarify that the underlying Layer-2 network remains secure. Steven Goldfeder, co-founder of Arbitrum’s parent company Offchain Labs, emphasized that the network’s native bridge was not affected. Goldfeder noted that the exploit was entirely isolated to the third-party smart contracts operated by AFX Trade, rather than a systemic failure of Arbitrum’s infrastructure.

Bridges have historically represented one of the most vulnerable attack vectors in the decentralized finance (DeFi) ecosystem. Because they hold massive pools of locked collateral to facilitate cross-chain transfers, they act as high-value targets for malicious actors. Unlike native network bridges, which undergo rigorous peer reviews and protocol-level testing, application-specific custody bridges often carry unique smart contract risks.

AFX Trade has suspended all operations on the affected bridge while it conducts a thorough forensic investigation alongside external security teams. The exchange assured users that its core trading engine, mainnet deployment, and non-bridge infrastructure remain unaffected by the breach.

In an effort to recover the stolen capital, AFX Trade’s head of growth, Ken C, publicly reached out to the exploiter. The protocol has offered a standard industry compromise: if the attacker returns 70% of the stolen funds, they can retain the remaining 30%—equivalent to roughly $7.2 million—as a legally sanctioned “white hat” bounty.

This negotiation tactic has become increasingly common in Web3 security incidents, where recovering assets via law enforcement can be exceptionally difficult due to the pseudonymous nature of blockchain transactions. Earlier this year, Solana-based Drift Protocol attempted a similar negotiation following a massive $285 million exploit.

The incident caps off a challenging period for decentralized derivatives platforms on Layer-2 networks. Just one week prior to the AFX Trade exploit, Ostium, another perpetuals trading platform on Arbitrum, lost $18 million after an attacker compromised its oracle private keys. Globally, DeFi protocols have lost more than $840 million to exploits and smart contract hacks in 2026 alone, highlighting persistent security challenges in the smart contract ecosystem.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button