AFX Trade, a decentralized perpetual contract platform on Arbitrum, has experienced a security incident. On-chain data shows that attackers obtained the validator signing key of the protocol's proprietary cross-chain bridge and transferred approximately 24.15 million USDC, almost wiping out the protocol's locked funds.
The original bridge was not breached.
Steven Goldfeder, co-founder of Offchain Labs, stated that the exploited bridge was not the native Arbitrum bridge, but a third-party bridge operated by AFX Trade. Security firm Blockaid also stated that the incident was not due to a malfunction in the bridge contract logic, but rather that the signing key for authorized withdrawals fell into the hands of attackers.
Blockaid stated that the attacker obtained a sufficient number of hot validator signatures and used them to approve a withdrawal of 24.15 million USDC. The bridge requires approximately two-thirds quorum approval, and the five hot validator signatures met this requirement. The contract then considered the withdrawal valid and released the funds after a 200-second dispute period.
Funds were transferred to Ethereum
The stolen USDC was subsequently transferred to Ethereum and exchanged for approximately 12,467 ETH, worth about $24 million at the time. On-chain tracking data shows that this batch of ETH is currently concentrated in a single wallet address.
This means that the attacker did not bypass the on-chain rules, but directly used the valid signature to complete the withdrawal. According to security agencies, the bridge's execution process followed the preset logic; the problem lay in the fact that the signature permissions themselves were controlled.
Almost empty agreement TVL
Prior to the attack, AFX Trade's trading activity had increased significantly. DefiLlama data shows that the protocol's daily perpetual contract trading volume rose to a multi-month high in mid-July, with users and deposits also increasing accordingly.
The approximately $24 million stolen is almost equal to AFX Trade's total locked value at the time. This means that the protocol's liquidity pool was nearly full when the attack occurred, thus amplifying the losses.

This incident also occurred amidst a surge in security breaches in the crypto industry. The report noted that the second quarter was one of the most severe periods for hacking attacks in recent years. Just a week prior, another Arbitrum ecosystem project, the RWA platform Ostium, also suffered a loss of approximately $18 million due to an oracle vulnerability.












