AFX Trade Bridge Exploited for $24M USDC on Arbitrum
A derivatives exchange protocol on Arbitrum fell victim to a bridge exploit on Tuesday, with attackers draining approximately 24.15 million USDC from the AFX Trade bridge contract. Security firm Blockaid detected the attack at 21:30 UTC on July 22.
AFX Trade Bridge Exploited for $24M USDC on Arbitrum
A derivatives exchange protocol on Arbitrum fell victim to a bridge exploit on Tuesday, with attackers draining approximately 24.15 million USDC from the AFX Trade bridge contract. Security firm Blockaid detected the attack at 21:30 UTC on July 22, flagging the unauthorized withdrawal as it unfolded.
The exploit targeted a bridge operated by derivatives exchange AFX and emptied nearly all of the USDC locked in the contract.
Blockaid
The attack represents another blow to bridge security in crypto infrastructure, a category that has suffered repeated high-profile breaches. The Ronin bridge hack in March 2022 drained $625 million. Poly Network's August 2021 exploit cost $611 million. Nomad's bridge drain in August 2022 reached $190 million. AFX's loss, while substantial, follows the pattern of targeted attacks on newer or lesser-audited bridge implementations rather than established infrastructure.
Arbitrum's native bridge was not compromised. Arbitrum co-founder Steven Goldfeder confirmed that the network's core cross-chain infrastructure remained secure. The vulnerability existed solely in AFX Trade's proprietary bridge architecture, limiting systemic risk to other protocols on the layer-2 network.
Bridges remain high-value targets with concentrated liquidity and complex smart contract logic. AFX's bridge, while purpose-built for a specific protocol, apparently lacked sufficient safeguards against the attack vector exploited on Tuesday. The specific technical mechanism behind the breach has not yet been disclosed, though Blockaid's rapid detection suggests the firm's monitoring systems caught the transaction in real time.
July has emerged as an exceptionally volatile month for crypto security, with the AFX exploit marking the 14th major incident recorded this month alone, already exceeding June's incident count. This uptick may reflect increased protocol complexity, a surge in cross-chain activity, or coordinated exploitation campaigns targeting vulnerabilities in newer implementations. The frequency suggests that security auditing and contract verification practices have not kept pace with the deployment velocity of new bridge and liquidity protocols.
AFX Trade's remediation options include emergency security audits, smart contract upgrades to patch the vulnerability, and potential insurance payouts if the protocol maintains coverage. Early detection by Blockaid provides a window for rapid response, though recovery of drained funds depends on whether the attacker moves the USDC through mixing services or bridges it to other chains. On-chain analysis may reveal the attacker's next steps and whether the funds remain recoverable.
As Arbitrum and other layer-2 networks attract more capital and protocols, the incentive for attackers to target bridge implementations grows proportionally. Established protocols like Arbitrum's native bridge benefit from extensive audits and battle-tested architecture. Newer entrants like AFX's bridge do not. The security gap between first-movers and newer protocols continues to widen, making protocol selection and risk assessment increasingly critical for users and institutions deploying capital across chains.
Update: July 23
AFX Trade has since offered the attacker a 30% bounty, roughly $7.2 million, in exchange for returning the remaining $16.95 million. The offer follows a well-worn playbook in DeFi recovery attempts: give the hacker a legal exit and a meaningful payday in hopes of avoiding the harder, slower path of chain analysis and law enforcement coordination.
The 30% bounty structure AFX is offering is not unusual. Several protocols have recovered meaningful portions of stolen funds through similar arrangements, most notably Poly Network, which famously saw its attacker return the entire $611 million haul. More often, though, bounty offers go unanswered, and recovery depends on whether the attacker makes errors during fund laundering that allow blockchain analytics firms to identify them. At $24 million, the haul is large enough to attract serious laundering effort, likely through mixers or cross-chain bridges, which will complicate any recovery attempt.






