{"id":35209,"date":"2026-07-23T02:27:47","date_gmt":"2026-07-23T02:27:47","guid":{"rendered":"https:\/\/bitunikey.com\/news\/afx-bridge-exploit-drains-24-15m-usdc-as-attacker-buys-12467-eth\/"},"modified":"2026-07-23T02:28:33","modified_gmt":"2026-07-23T02:28:33","slug":"afx-bridge-exploit-drains-24-15m-usdc-as-attacker-buys-12467-eth","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/afx-bridge-exploit-drains-24-15m-usdc-as-attacker-buys-12467-eth\/","title":{"rendered":"AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">AFX suffered a $24.15 million USDC loss after an attacker targeted a cross-chain bridge linked to the trading protocol on July 22. <\/p>\n<div id=\"cn-block-summary-block_034b64058d5fdb18de93a7e770c2bec0\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>AFX\u2019s cross-chain bridge lost $24.15 million USDC while Arbitrum\u2019s native bridge remained unaffected during attack.<\/li>\n<li>The exploiter moved stolen USDC to Ethereum and converted the proceeds into 12,467.5 ETH afterward.<\/li>\n<li>Security firms are tracing the stolen funds as AFX and Arbitrum teams investigate the breach.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The incident triggered an investigation by Blockaid and the Arbitrum team, while on-chain trackers followed the stolen funds to Ethereum.<\/p>\n<p>The attack did not affect Arbitrum\u2019s native bridge. AFX operates its own sovereign Layer 1 for perpetual trading but accepts USDC deposits through Arbitrum. The affected infrastructure was a third-party bridge operated by AFX rather than Arbitrum\u2019s core bridge.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>AFX bridge loses $24.15 million USDC<\/strong><\/h2>\n<p>Blockaid said it <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/blockaid_\/status\/2080080240265621680?s=20\" target=\"_blank\" rel=\"nofollow\">detected<\/a> the exploit at 9:30 p.m. UTC on July 22. The firm said the attack targeted a bridge operated by AFX and drained about 24.15 million USDC. An Arbiscan record shows a successful transfer of 24,150,000 USDC from the bridge contract to the recipient address at 9:30:25 p.m. UTC.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/AFX_XYZ?ref_src=twsrc%5Etfw\">@AFX_XYZ<\/a>, a protocol on <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/arbitrum?ref_src=twsrc%5Etfw\">@arbitrum<\/a>. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.<\/p>\n<p>Our team has been working with the incredible folks on\u2026 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/0Qd9ve5gPB\">https:\/\/t.co\/0Qd9ve5gPB<\/a><\/p>\n<p>\u2014 Blockaid (@blockaid_) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/blockaid_\/status\/2080080240265621680?ref_src=twsrc%5Etfw\">July 22, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The security firm said it was working with the Arbitrum team to respond, contact the affected protocol and help contain the stolen funds. Based on the public updates reviewed at publication time, no recovery had been confirmed.\u00a0<\/p>\n<p>AFX had also not published a verified technical postmortem explaining how the attacker gained authorization to withdraw the funds. The protocol had not announced a recovery plan.<\/p>\n<p>Offchain Labs co-founder Steven Goldfeder confirmed that the suspicious transaction came from a third-party protocol. He also separated the AFX incident from Arbitrum\u2019s own bridge infrastructure.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe\u2019re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,\u201d Goldfeder said.\u00a0<\/p>\n<\/blockquote>\n<p>He added that the team would coordinate with the third-party protocol and share more details when available.<\/p>\n<p>AFX uses Arbitrum as a route for USDC deposits while running its trading system on a dedicated Layer 1. AFX describes itself as a decentralized derivatives platform built around a sovereign execution environment. A recent protocol post also said users could deposit USDC from Arbitrum before accessing its perpetual markets.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Exploiter converts stolen USDC into ETH<\/strong><\/h2>\n<p>PeckShield said the attacker moved the stolen USDC from Arbitrum to Ethereum and converted the proceeds into 12,467.5 ETH. Lookonchain separately <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/lookonchain\/status\/2080092059252486487?s=20\" target=\"_blank\" rel=\"nofollow\">reported<\/a> that the exploiter bought about 12,467 ETH at an average price near $1,937 per ETH after moving the funds.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/hashtag\/PeckShieldAlert?src=hash&amp;ref_src=twsrc%5Etfw\">#PeckShieldAlert<\/a> <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/AFX_XYZ?ref_src=twsrc%5Etfw\">@AFX_XYZ<\/a> on <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/hashtag\/Arbitrum?src=hash&amp;ref_src=twsrc%5Etfw\">#Arbitrum<\/a> has been exploited for ~$24M USDC. The exploiter has bridged the stolen funds from <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/hashtag\/Abitrum?src=hash&amp;ref_src=twsrc%5Etfw\">#Abitrum<\/a> to <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/hashtag\/Ethereum?src=hash&amp;ref_src=twsrc%5Etfw\">#Ethereum<\/a> and swapped them for 12,467.5 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/search?q=%24ETH&amp;src=ctag&amp;ref_src=twsrc%5Etfw\">$ETH<\/a>, currently sitting in 0x6276\u2026ebAC.<a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/INZ7ZxtRhE\">https:\/\/t.co\/INZ7ZxtRhE<\/a> <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/fUHFfEn1F5\">pic.twitter.com\/fUHFfEn1F5<\/a><\/p>\n<p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2080088731558801909?ref_src=twsrc%5Etfw\">July 23, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The conversion moved the stolen value from a U.S. dollar-pegged stablecoin into Ether, exposing the holdings to ETH price movements. Security teams continued tracing the funds after the swap. At publication time, the reviewed sources did not confirm that Circle had frozen the USDC before conversion or that any of the ETH had been recovered.<\/p>\n<p>The attack adds to several bridge-related security incidents this year. As crypto.news previously reported, Stake DAO closed its vsdCRV bridge after an unauthorized mint on Arbitrum in May. The project said it secured the token\u2019s mainnet backing and contained the incident to the affected bridge.<\/p>\n<p>Earlier in April, a larger exploit hit Kelp DAO\u2019s LayerZero-powered bridge. Attackers drained roughly 116,500 rsETH worth about $292 million. Arbitrum later froze more than 30,000 ETH linked to that attacker after the funds moved onto Arbitrum One.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Investigation focuses on AFX-operated infrastructure<\/strong><\/h2>\n<p>The investigation now centers on the AFX-operated bridge and the authorization process behind the 24.15 million USDC withdrawal. The confirmed transaction shows that the bridge contract finalized the transfer, but public statements do not yet establish the verified root cause. A full postmortem may determine whether the incident involved compromised validator credentials, faulty access controls or another weakness.<\/p>\n<p>The main confirmed point is that the exploit affected infrastructure operated by AFX rather than Arbitrum\u2019s native bridge. Blockaid and Offchain Labs both made that separation clear in their initial responses. The Arbitrum network continued operating, and reviewed reports showed no loss from its native bridge.<\/p>\n<p>The incident also places attention on AFX\u2019s deposit infrastructure. The protocol has promoted USDC deposits from Arbitrum as an entry route into its trading platform. Any changes to deposits, withdrawals or bridge operations will depend on the protocol\u2019s response and the ongoing investigation.<\/p>\n<p>The case remains developing. The confirmed loss stands at about $24.15 million in USDC, while on-chain trackers have traced the stolen value into roughly 12,467 ETH on Ethereum. Further updates are expected from AFX, Blockaid and the Arbitrum team as they review the breach and track the attacker\u2019s funds.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AFX suffered a $24.15 million USDC loss after an attacker targeted a cross-chain bridge linked to the trading protocol on July 22. Summary AFX\u2019s cross-chain bridge lost $24.15 million USDC&hellip;<\/p>\n","protected":false},"author":1,"featured_media":29669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35209","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35209","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35209"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35209\/revisions"}],"predecessor-version":[{"id":35210,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35209\/revisions\/35210"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/29669"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35209"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35209"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35209"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}