AFX Trade has temporarily suspended operations of its Arbitrum-operated USDC custody bridge following a significant drain of approximately $24.15 million in USDC on July 22, 2026. The incident, first flagged by blockchain security firm Blockaid at 21:30 UTC, appears to have targeted AFX’s specific bridge infrastructure rather than the native Arbitrum bridge. The project is currently conducting an in-depth investigation into the precise root cause, while various security firms are actively monitoring the movement of the illicitly acquired funds to facilitate potential recovery efforts.
AFX Trade Halts Bridge Operations Amidst Substantial USDC Loss
In a swift response to the security breach, AFX Trade confirmed the incident affecting its USDC custody bridge on the Arbitrum network. This bridge plays a critical role in facilitating USDC deposits and withdrawals within AFX’s broader trading ecosystem. Upon immediate detection of the anomaly, the project stated that bridge operations were promptly halted, and its established incident response protocols were activated.
An official statement from AFX Trade disseminated via social media platform X (formerly Twitter) read: "AFX is aware of an incident involving the AFX-operated USDC custody bridge on Arbitrum. Upon detecting the incident, we immediately suspended bridge operations and initiated our incident response procedures. Our engineering and security teams are actively investigating the root cause." This proactive measure aimed to contain further potential losses and to initiate a comprehensive forensic analysis.
Initial assessments strongly suggest that the security compromise was confined to the project-specific custody bridge, with no indications of a breach affecting AFX’s core trading infrastructure, its mainnet, or the underlying Arbitrum network itself. This distinction is crucial, as it narrows the scope of the investigation and potential vulnerabilities.
Echoing these sentiments, Offchain Labs, the development team behind Arbitrum, provided further clarification. Steven Goldfeder, co-founder and CEO of Offchain Labs, stated that the transactions associated with the exploit originated from a third-party protocol. Crucially, Goldfeder emphasized that Arbitrum’s native bridge remained secure and was neither compromised nor exploited. This corroboration reinforces the understanding that the financial loss is attributable to vulnerabilities within AFX’s proprietary bridge solution, despite the substantial scale of the drained assets.
Chronology of the Incident and Fund Movement
The security breach was first alerted by Blockaid at 21:30 UTC on July 22, 2026. Within a short period, approximately $24.15 million in USDC was siphoned from the AFX-operated bridge. This figure represents a significant portion of the Total Value Locked (TVL) in the AFX Bridge prior to the incident. Data from DeFi analytics platform DefiLlama indicated that AFX Bridge held roughly $24.18 million in TVL, predominantly on Arbitrum, suggesting that nearly all assets within the bridge were exposed.
Following the successful drain, the perpetrator initiated a transfer of the stolen USDC from the Arbitrum network to the Ethereum mainnet. Blockchain analytics firm PeckShield diligently tracked the flow of these funds. Their analysis revealed that the attacker subsequently swapped the acquired USDC for approximately 12,467.5 Ether (ETH). This substantial amount of ETH was then consolidated into a specific Ethereum wallet, identified as 0x6276…ebAC.
The nature of the exploited assets, particularly USDC, presents distinct recovery challenges compared to native cryptocurrencies like ETH. USDC, a stablecoin issued by Circle, possesses a mechanism for token freezing at the smart contract level under specific regulatory or security circumstances. In contrast, ETH, once swapped and consolidated into a wallet, becomes considerably more difficult to recover through direct token-level interventions. Recovery in such scenarios typically relies heavily on sophisticated on-chain monitoring, intelligence gathering, and coordinated efforts with cryptocurrency exchanges to potentially intercept funds if they are moved to centralized platforms.

AFX Trade’s Response and Recovery Efforts
In the wake of the exploit, AFX Trade has publicly committed to a multi-faceted approach to address the situation and mitigate further risks. The project has engaged with multiple blockchain security partners to assist in the ongoing investigation and to bolster its security posture.
Security firm SlowMist noted that the stolen funds remained in the attacker’s address. This address has been formally reported to the Crypto Defense Alliance (CDA), a collaborative initiative comprising exchanges and other key ecosystem participants dedicated to combating illicit activities in the cryptocurrency space. AFX confirmed that this associated address is under continuous surveillance by various stakeholders within the ecosystem.
Furthermore, AFX has enlisted the expertise of Zellic, the firm that previously conducted an audit of the bridge’s code. Zellic’s involvement is expected to provide critical insights into any potential code vulnerabilities that may have been exploited. A comprehensive technical postmortem, to be released by AFX in conjunction with the involved security firms, will form the basis for determining the precise attack vector. This analysis will investigate possibilities ranging from smart contract flaws and validator misconfigurations to key management issues and backend signing processes.
In parallel with the formal investigation, AFX has publicly amplified a white-hat settlement offer extended by Ken / Supercube, Head of Growth at AFX. The offer proposes that the party responsible for the bridge incident return 70% of the stolen assets to a designated address (0x222B…9f1B) while being allowed to retain the remaining 30% as a bounty for reporting the vulnerability. This approach, while controversial, aims to incentivize the return of funds and potentially mitigate further losses. The offer, posted on X, stated: "We are extending a white hat settlement offer to the party responsible for the recent bridge incident. Return 70% of the stolen assets to the following address: 0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1B. You may retain the remaining 30% as a white hat bounty. Our priority is…"
AFX’s current communication strategy emphasizes two primary objectives: safeguarding the community and maximizing the potential for recovering user assets. However, as of the latest updates, there has been no public confirmation regarding the return of any portion of the stolen funds.
Investigating the Root Cause: Infrastructure Vulnerability Suspected
As of this report, AFX has not definitively disclosed the specific attack vector employed by the perpetrator. The project has consistently reiterated that its investigation is ongoing and that further details will be provided as verified information becomes available. This leaves the precise nature of the exploit – whether a smart contract exploit or a compromise of validator keys – subject to assessments from security sources and the eventual findings of the postmortem.
However, several prominent security researchers and decentralized finance data aggregators have broadly classified the event as an infrastructure incident. SlowMist, for instance, described the exploit as targeting AFX’s cross-chain and USDC custody bridge on Arbitrum. Their analysis suggests that the attacker may have leveraged compromised validator hot keys to achieve the necessary quorum for fund disbursement. This aligns with the classification in the DefiLlama Hacks database, which records a $24.15 million loss for AFX Bridge and categorizes it as "Infrastructure" with the technique labeled "Private Key Compromised."
If the forthcoming postmortem report confirms this classification, the AFX incident will serve as a stark reminder of the operational risks inherent in bridge infrastructure. These risks encompass the secure management of signing keys, the integrity of validator setups, the robustness of custody processes, and the efficacy of withdrawal verification mechanisms. Bridges, by their very design, often hold substantial asset volumes within smart contracts or custody layers. Consequently, any procedural flaws in their verification systems can lead to highly concentrated and significant financial losses, impacting a large user base simultaneously.
AFX has yet to release specific details regarding the number of affected keys or validators, the precise role of the bridge code in the exploit, or any potential user reimbursement plans. The project has also not confirmed any successful recovery of the stolen funds. The final, verified technical root cause of this incident remains pending and is under active investigation by AFX and its security partners. The implications of this exploit extend beyond AFX, highlighting ongoing challenges in securing cross-chain interoperability solutions, a critical component of the broader Web3 ecosystem. The industry continues to grapple with ensuring the security and reliability of these vital financial conduits.








