Ethereum: Arbitrum ecosystem AFX Trade suffers theft of approximately $24.15 million
CoinDesk
07-23 13:07
Ai Focus
AFX Trade lost approximately $24.15 million due to the theft of its proprietary bridge verification key, while the Arbitrum native bridge was unaffected.
Helpful
No.Help

AFX Trade, a decentralized perpetual contract platform on Arbitrum, has experienced a security incident. On-chain data shows that attackers obtained the validator signing key of the protocol's proprietary cross-chain bridge and transferred approximately 24.15 million USDC, almost wiping out the protocol's locked funds.

The original bridge was not breached.

Steven Goldfeder, co-founder of Offchain Labs, stated that the exploited bridge was not the native Arbitrum bridge, but a third-party bridge operated by AFX Trade. Security firm Blockaid also stated that the incident was not due to a malfunction in the bridge contract logic, but rather that the signing key for authorized withdrawals fell into the hands of attackers.

Blockaid stated that the attacker obtained a sufficient number of hot validator signatures and used them to approve a withdrawal of 24.15 million USDC. The bridge requires approximately two-thirds quorum approval, and the five hot validator signatures met this requirement. The contract then considered the withdrawal valid and released the funds after a 200-second dispute period.

Funds were transferred to Ethereum

The stolen USDC was subsequently transferred to Ethereum and exchanged for approximately 12,467 ETH, worth about $24 million at the time. On-chain tracking data shows that this batch of ETH is currently concentrated in a single wallet address.

This means that the attacker did not bypass the on-chain rules, but directly used the valid signature to complete the withdrawal. According to security agencies, the bridge's execution process followed the preset logic; the problem lay in the fact that the signature permissions themselves were controlled.

Almost empty agreement TVL

Prior to the attack, AFX Trade's trading activity had increased significantly. DefiLlama data shows that the protocol's daily perpetual contract trading volume rose to a multi-month high in mid-July, with users and deposits also increasing accordingly.

The approximately $24 million stolen is almost equal to AFX Trade's total locked value at the time. This means that the protocol's liquidity pool was nearly full when the attack occurred, thus amplifying the losses.

This incident also occurred amidst a surge in security breaches in the crypto industry. The report noted that the second quarter was one of the most severe periods for hacking attacks in recent years. Just a week prior, another Arbitrum ecosystem project, the RWA platform Ostium, also suffered a loss of approximately $18 million due to an oracle vulnerability.

Tip
$0
Like
0
Save
0
Views 131
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: During the sharp decline in South Korea, Upbit achieved a single-hour trading volume of 11.5 trillion Korean won
South Korean exchange Upbit saw a one-hour trading volume of 11.5 trillion Korean won during the flash crash period, with XRP having the highest trading proportion; the entire market cleared approximately 523 million US dollars in one hour.
Cryptonews
·2026-08-23 18:24:12
28
web3: South Korean crypto trading is picking up, with Upbit transaction volume soaring by 273%
South Korean crypto trading activity has picked up, with Upbit and Bithumb seeing a significant increase in 24-hour trading volume. XRP leads the Upbit trading rankings.
CoinPedia
·2026-08-23 17:32:39
29
The Sandbox Suspends Cross-Chain Bridge Between Base and BNB Chain: Unsecured SAND Why Can't We Just Look at the Coin Minting Volume?
On August 22, The Sandbox stated that a vulnerability was discovered in its SAND cross-chain bridge on Base and BNB Smart Chain. Attackers were able to mint tokens without the corresponding Ethereum SAND locking support. The team subsequently suspended the related cross-chain functionality and claimed that the vulnerability had been contained. The core issue of this incident is not merely the simple "minting" of additional tokens, but rather the disruption of the most fundamental accounting relationships between cross-chain assets: the mapped tokens on the target chain should correspond one-to-one with the assets locked or destroyed on the source chain; once unsecured minting occurs, the market can no longer assume equivalence between SAND on different chains.
币界网
·2026-08-23 12:29:19
125
Flipkart Accelerates to Catch Up with India's Top Three Instant Retail Players
On the Minutes of Flipkart, daily orders reached around 1.1 to 1.2 million, approaching the Instamart. Competition in India's instant retail sector continues to heat up.
TechCrunch
·2026-08-23 11:22:37
39
web3 : PEPE rises to 0.00000411, contract holdings surge
PEPE rose by nearly 18%, with futures trading volume and open interest contracts also increasing simultaneously. The market is focusing on the 0.000005 level.
CoinPedia
·2026-08-22 18:28:39
60
View More