{"id":24376,"date":"2026-07-24T04:46:03","date_gmt":"2026-07-24T04:46:03","guid":{"rendered":"https:\/\/nft.runfyers.com\/index.php\/2026\/07\/24\/afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum-nft-plazas-afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum\/"},"modified":"2026-07-24T04:46:03","modified_gmt":"2026-07-24T04:46:03","slug":"afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum-nft-plazas-afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum","status":"publish","type":"post","link":"https:\/\/nft.runfyers.com\/index.php\/2026\/07\/24\/afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum-nft-plazas-afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum\/","title":{"rendered":"AFX Trade Bridge Exploit Drains $24.15M USDC on Arbitrum &#8211; NFT Plazas AFX Trade Bridge Exploit Drains $24.15M USDC on Arbitrum"},"content":{"rendered":"<p><\/p>\n<div>\n<p><b>AFX Trade <\/b><span style=\"font-weight: 400;\">has paused its Arbitrum-operated USDC custody bridge after approximately <\/span><b>$24.15 million<\/b><span style=\"font-weight: 400;\"> in USDC was drained on July 22, 2026, according to a <\/span><a href=\"https:\/\/x.com\/blockaid_\/status\/2080080240265621680?s=20\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\"><span style=\"font-weight: 400;\">Blockaid alert<\/span><\/a><span style=\"font-weight: 400;\">. The incident was detected at 21:30 UTC, targeting AFX\u2019s bridge infrastructure rather than Arbitrum\u2019s native bridge. The exact root cause remains under investigation by the project, while security firms monitor the flow of stolen funds to support recovery efforts.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"AFX_Pauses_Bridge_After_2415M_USDC_Drain\"\/><b>AFX Pauses Bridge After $24.15M USDC Drain<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">AFX confirmed an incident involving its AFX-operated USDC custody bridge on Arbitrum, which handles USDC deposits\/withdrawals for the project\u2019s trading ecosystem. Immediately upon detecting the incident, AFX stated it paused bridge operations and activated its incident response procedures.<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">AFX is aware of an incident involving the AFX-operated USDC custody bridge on Arbitrum.<br \/>Upon detecting the incident, we immediately suspended bridge operations and initiated our incident response procedures. Our engineering and security teams are actively investigating the root\u2026<\/p>\n<p>\u2014 AFX Trade (@AFX_XYZ) <a href=\"https:\/\/x.com\/AFX_XYZ\/status\/2080126901205770734?ref_src=twsrc%5Etfw\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\">July 23, 2026<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">Initial assessments indicate the incident appears isolated to the project-operated custody bridge. AFX stated that its trading infrastructure, AFX mainnet, and the Arbitrum network were not compromised.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Offchain Labs shared a similar message. Steven Goldfeder, co-founder and CEO of Offchain Labs, stated that the relevant transaction originated from a third-party protocol, while Arbitrum\u2019s native bridge was neither hacked nor exploited. This information further indicates that the damage was concentrated on AFX\u2019s bridge, though the scale of the loss for the project remains substantial.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Funds_Flow_to_Ethereum\"\/><b>Funds Flow to Ethereum<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Blockaid reported that the exploit was detected at 21:30 UTC on July 22, 2026, with approximately $24.15 million in USDC drained from the AFX-operated bridge. This figure almost matches AFX Bridge\u2019s pre-incident TVL. DefiLlama data logged AFX Bridge with around $24.18 million in TVL, all situated on Arbitrum, representing nearly the entirety of the locked assets in the bridge.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After draining the USDC, the attacker transferred the assets from Arbitrum to Ethereum. PeckShield tracked the funds flow, noting that the stolen USDC was subsequently swapped into approximately <\/span><b>12,467.5 ETH<\/b><span style=\"font-weight: 400;\">. This ETH was traced back to wallet <strong>0x6276\u2026ebAC<\/strong>.<\/span><\/p>\n<div id=\"attachment_98403\" style=\"width: 1622px\" class=\"wp-caption alignnone\"><noscript><\/noscript><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-98403\" class=\"lazyload size-full wp-image-98403\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/HN31rEOaAAEUo6z.jpeg\" alt=\"Attacker wallet holding swapped ETH\" width=\"1612\" height=\"864\"\/><\/p>\n<p id=\"caption-attachment-98403\" class=\"wp-caption-text\">Attacker wallet holding swapped ETH. Source: PeckShield<\/p>\n<\/div>\n<p><span style=\"font-weight: 400;\">USDC is a stablecoin issued by Circle and can be frozen at the token contract level under certain circumstances. ETH lacks a similar mechanism, so once assets are swapped and consolidated into an Ethereum wallet, recovery relies more heavily on on-chain monitoring and exchange coordination.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"AFX_Works_to_Recover_Funds\"\/><b>AFX Works to Recover Funds<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">AFX stated it is working with blockchain security partners as the investigation continues. Meanwhile, SlowMist noted that the stolen funds remain in the attacker\u2019s address, which has been reported to the <\/span><b>Crypto Defense Alliance (CDA)<\/b><span style=\"font-weight: 400;\">\u2014a collaborative network of exchanges and ecosystem partners. AFX said the associated address is being monitored by ecosystem stakeholders.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The project also mentioned that Zellic, the firm that previously audited the bridge code, has been invited to assist in the investigation. A technical postmortem from AFX and security firms will serve as the basis to determine whether the incident involved code vulnerabilities, validator setup, key management, or backend signing flows.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In parallel with the investigation, AFX amplified a white-hat settlement offer from Ken \/ Supercube, Head of Growth at AFX. The offer requests the party responsible for the bridge incident to return 70% of the stolen assets to address <strong>0x222B\u20269f1B<\/strong>, while retaining the remaining 30% as a white-hat bounty.<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We are extending a white hat settlement offer to the party responsible for the recent bridge incident.<\/p>\n<p>Return 70% of the stolen assets to the following address:<br \/>0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1B<\/p>\n<p>You may retain the remaining 30% as a white hat bounty.<\/p>\n<p>Our priority is\u2026<\/p>\n<p>\u2014 Ken \/ Supercube\ud83e\uddca (@supercubeguy) <a href=\"https:\/\/x.com\/supercubeguy\/status\/2080162934140109214?ref_src=twsrc%5Etfw\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\">July 23, 2026<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">AFX\u2019s recovery messaging currently focuses on two objectives: protecting the community and maximizing the potential recovery of user assets. However, at the time of writing, there is no public confirmation that any portion of the stolen funds has been returned.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Root_Cause_Still_Under_Investigation\"\/><b>Root Cause Still Under Investigation<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">AFX has not yet announced the final attack vector. In official updates, the project only stated that the investigation is ongoing and that further information will be provided as verified data becomes available. Therefore, there is currently no basis for a definitive conclusion on whether this was a smart contract exploit or a validator key compromise, beyond assessments from security sources.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Nevertheless, several security sources and DeFi data aggregators have categorized the event as an infrastructure incident. SlowMist described it as an exploit targeting AFX\u2019s cross-chain\/USDC custody bridge on Arbitrum, suggesting the attacker used compromised validator hot keys to achieve a payout quorum. The DefiLlama Hacks database also recorded a $24.15 million loss for AFX Bridge, classifying it as \u201cInfrastructure\u201d with the technique labeled \u201cPrivate Key Compromised.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If the postmortem confirms this classification, the AFX incident will serve as another example of operational risks at the bridge layer, including signing keys, validator setups, custody processes, and withdrawal verification mechanisms. Bridges typically hold large asset volumes in contracts or custody layers, making procedural flaws in verification capable of causing concentrated losses.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AFX has not disclosed the number of affected keys or validators, the specific role of the bridge code, or user reimbursement plans. The project has also not confirmed any recovery from the stolen funds. The final technical root cause remains pending verification from AFX and investigative teams.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/nftplazas.com\/afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AFX Trade has paused its Arbitrum-operated USDC custody bridge after approximately $24.15 million in USDC was drained on July 22, 2026, according to a Blockaid alert. The incident was detected at 21:30 UTC, targeting AFX\u2019s bridge infrastructure rather than Arbitrum\u2019s native bridge. The exact root cause remains under investigation by the project, while security firms [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24377,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[16],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/07\/2307-1.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24376"}],"collection":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=24376"}],"version-history":[{"count":0,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24376\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/24377"}],"wp:attachment":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=24376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=24376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=24376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}