# AFX Trade bridge drained of $24M after keys compromised

> AFX Trade lost about $24.15M USDC on July 22 after attackers used compromised hot-validator keys on its Arbitrum custody bridge, then swapped the haul for ~12,467 ETH.

- **Source:** https://ptycoin.com/en/posts/2026-07-24-afx-trade-bridge-24m-usdc-drain/
- **Published:** 2026-07-24
- **Category:** News
- **Author:** Mateo
- **Tags:** security, defi, stablecoins, exchanges, self-custody

---


**AFX Trade**, a USDC-settled perpetuals platform that routes deposits through an Arbitrum custody bridge, was drained of about **$24.15 million USDC** on **July 22, 2026** after an attacker used compromised **hot-validator signing keys** to approve a full withdrawal. Security firm [Blockaid](https://x.com/blockaid_/status/2080080240265621680) flagged the drain at **21:30 UTC**; the on-chain [Arbiscan transfer](https://arbiscan.io/tx/0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b) shows **24,150,000 USDC** leaving the bridge contract. [CoinDesk](https://www.coindesk.com/tech/2026/07/23/arbitrum-based-afx-trade-drained-of-usd24-million-after-bridge-keys-compromised), [The Defiant](https://thedefiant.io/news/hacks/attacker-drains-usd24m-in-usdc-from-afx-bridge-on-arbitrum), and [BeInCrypto](https://beincrypto.com/afx-arbitrum-bridge-exploit-24m/) all match that timeline.

## What was hit — and what was not

AFX (Anti-Fragile Exchange) markets itself as a derivatives venue for USDC-margined perps with high leverage on crypto and traditional underlyings, with user deposits entering through a bridge contract on Arbitrum ([project site](https://www.afx.xyz)). That **AFX-operated bridge** is the target. It is not Arbitrum's native bridge.

[Steven Goldfeder](https://x.com/sgoldfed/status/2080071210847674709), co-founder of Arbitrum developer Offchain Labs, said the transaction came from a third-party protocol and that **the Arbitrum native bridge was not hacked or exploited**. Blockaid said the same: the incident was **specific to a bridge AFX operates**, and the firm is coordinating with Arbitrum and the protocol to contain stolen funds.

[DefiLlama](https://defillama.com/protocol/afx-bridge) put the bridge near **$24.2 million** in USDC before the attack, so the drain emptied nearly the entire float users rely on to move collateral in and out.

## How the keys did the work

Public reconstructions from CoinDesk and The Cryptonomist agree on the mechanism:

1. The attacker obtained enough **hot-validator private keys** for the bridge's signing set.
2. **Five** hot-validator signatures met the roughly **two-thirds quorum** needed to authorize a withdrawal.
3. The bridge proposal spent a short **~200-second dispute window**, then released **24.15 million USDC** to the attacker wallet because the contract treated the signatures as valid.
4. The haul was bridged to **Ethereum** and swapped for about **12,467 ETH** (roughly **$1,937** per ETH at the time), per [PeckShield](https://x.com/PeckShieldAlert/status/2080088731558801909) and on-chain trackers cited by The Defiant and Lookonchain.

The contracts did what they were coded to do. There was no flash-loan pool skew and no oracle fake-out. The failure was **off-chain key control**: once enough validator keys sit with an attacker, a "valid" withdrawal is just another signed message.

## White-hat offer on the table

After the drain, AFX growth lead **Ken C** floated a public white-hat path: the exploiter keeps **30%** (about **$7.2 million**) if they return **70%** of the stolen funds, according to [Crypto Briefing](https://cryptobriefing.com/afx-trade-exploiter-white-hat-deal/) and matching industry coverage. That is a recovery negotiation, not a guarantee. Once USDC is swapped into ETH and moved across addresses, exchange freezes and law-enforcement seizures become harder.

## A crowded July for bridges and perps

This hit lands in a rough month. BeInCrypto, citing DefiLlama and security tallies, put **July 2026 hack losses near $97 million** after AFX — already above June's ~$75 million. On Arbitrum alone, [Ostium](/en/posts/2026-07-17-ostium-18m-oracle-keeper-exploit/) halted trading mid-month after an oracle-related vault drain reported near **$18 million**. Different failure modes (oracle vs keys), same lesson: **high-leverage or high-TVL products still depend on operational security outside the audited Solidity**.

Latin American traders and desks that park USDC on L2 perps or bridge collateral through custom gates feel this as product risk, not theory. Remittance and treasury flows already favor dollar stablecoins; a bridge that can empty when **hot keys** leak is inventory risk for anyone who left deposits in protocol custody rather than in their own wallet.

## What to watch

- **Whether any of the ~12,467 ETH hits exchange deposit addresses** that can freeze inflows (trackers are watching the flow).
- **Whether the 30% bounty produces a partial return**, and whether AFX posts a full loss and user-compensation plan.
- **Bridge resume criteria**: new key ceremony, longer dispute windows, cold quorum thresholds, and independent confirmation that the old signing set is retired.

If you still have funds on AFX or any third-party bridge, treat pause and status posts as operational facts. Smart-contract audits do not substitute for **who holds the signing keys**. Prefer self-custody for balances you do not need as open margin, and size bridge deposits to what you can afford to see frozen or lost. Not financial advice.

---

Source: PTYcoin — https://ptycoin.com/en/posts/2026-07-24-afx-trade-bridge-24m-usdc-drain/. Free to read and cite with attribution to ptycoin.com. AI-usage terms: https://ptycoin.com/en/ai-usage/
