AFX Trade Loses $24M in Bridge Key Compromise, Offers Hacker $7.2M to Return Funds
An attacker drained $24.15 million in USDC from AFX Trade on July 23, 2026, exploiting compromised validator signing keys on the DEX's custody bridge. AFX Trade offered a 30% bounty to recover the remaining funds, following a pattern of bridge exploits that have cost the crypto ecosystem billions.
AFX Trade Loses $24M in Bridge Key Compromise, Offers Hacker $7.2M to Return Funds
An attacker drained $24.15 million in USDC from AFX Trade on July 23, 2026, exploiting a compromised set of validator signing keys on a custody bridge the Arbitrum-based perpetual futures DEX operates. The stolen funds moved to Ethereum almost immediately after the breach.
AFX Trade has since offered the attacker a 30% bounty, roughly $7.2 million, in exchange for returning the remaining $16.95 million. The offer follows a well-worn playbook in DeFi recovery attempts: give the hacker a legal exit and a meaningful payday in hopes of avoiding the harder, slower path of chain analysis and law enforcement coordination.
The distinction between AFX's bridge and the Arbitrum protocol itself matters here. Arbitrum is a Layer 2 rollup that settles transactions on Ethereum, and its core infrastructure was not touched. What failed was AFX Trade's proprietary custody bridge, a piece of off-chain infrastructure the protocol uses to move assets between chains. When an attacker gains control of the validator signing keys that authorize bridge transactions, they can effectively instruct the bridge to release funds to any address they choose. No smart contract bug required. No protocol flaw to patch. Just a set of private keys in the wrong hands.
That operational reality puts this incident squarely in the category of key management failure rather than architectural vulnerability, but the $24 million loss is no less real for users who held funds on the platform.
Bridge infrastructure has been the single most productive hunting ground for crypto attackers over the past four years. The Ronin bridge hack in March 2022 netted $625 million after attackers compromised validator keys for the Axie Infinity sidechain. Poly Network lost $611 million in August 2021 to a smart contract exploit. Nomad's bridge drained $190 million in August 2022 after a routine upgrade introduced a critical flaw. The common thread across nearly all of these is that bridges sit at the intersection of two separate security domains and must be trusted by both. That boundary is structurally difficult to harden, and it consistently attracts the most sophisticated attackers in the space.
The 30% bounty structure AFX is offering is not unusual. Several protocols have recovered meaningful portions of stolen funds through similar arrangements, most notably Poly Network, which famously saw its attacker return the entire $611 million haul. More often, though, bounty offers go unanswered, and recovery depends on whether the attacker makes errors during fund laundering that allow blockchain analytics firms to identify them. At $24 million, the haul is large enough to attract serious laundering effort, likely through mixers or cross-chain bridges, which will complicate any recovery attempt.
For the broader DeFi space, the AFX incident reinforces a structural lesson that has not fully landed despite years of costly repetition: the security of a protocol is only as strong as the weakest piece of infrastructure it depends on. A perpetual futures DEX can have flawless on-chain logic and still lose everything if the bridge moving collateral in and out is poorly secured. Multi-signature key schemes, hardware security modules, and time-locked withdrawals exist precisely to raise the cost of this kind of attack. Whether AFX had any of those controls in place, and why they failed, will be the central question as the post-mortem develops.



