AFX Trade, a decentralized perpetuals exchange operating on the Arbitrum network, has been drained of approximately $24.15 million in a security breach targeting its proprietary bridge. The incident, detected on July 22, 2026, by security firm Blockaid, highlights a continuing trend of attackers focusing on off-chain infrastructure rather than smart contract vulnerabilities.
The Nature of the Attack
According to blockchain data, the attacker did not exploit a flaw in the protocol’s smart contract code. Instead, they compromised the private validator signing keys—hot keys held off-chain by the bridge operators. By gaining access to these keys, the attacker was able to authorize a withdrawal of 24,150,000 USDC, meeting the two-thirds quorum required by the bridge’s security design. The protocol’s contract, operating exactly as programmed, verified the signatures and processed the transaction after the mandatory 200-second dispute period.
Following the unauthorized withdrawal, the stolen funds were bridged from Arbitrum to the Ethereum network, where they were swapped into roughly 12,467 ETH. Current on-chain tracking identifies the funds as resting in a single wallet.
Institutional Response and Impact
Steven Goldfeder, co-founder of Offchain Labs, the developer of the Arbitrum network, emphasized that the Arbitrum native bridge remains secure. He clarified that the incident was contained to the third-party protocol’s infrastructure, stating, “We’re aware of a report of a bridge hack on Arbitrum and are investigating.”
The breach represents nearly the entirety of AFX Trade’s total value locked (TVL). The timing of the hack is particularly significant, as it follows a period of rapid growth for the exchange, which had seen its daily perpetuals trading volume reach multi-month highs just days before the incident.
A Volatile Month for DeFi Security
The AFX Trade exploit is the 14th security incident recorded in July 2026, contributing to a total of approximately $97 million in losses for the month. This surpasses the total losses recorded in June, which stood at $75.32 million. The series of attacks underscores the systemic risks inherent in cross-chain bridge architecture, where off-chain key management often serves as the primary point of failure for decentralized protocols.

