AFX Trade, a decentralized exchange platform for perpetual contracts within the Arbitrum ecosystem, has experienced a security incident. Security firm Blockaid stated that the USDC escrow bridge operated by the platform was attacked, resulting in a loss of approximately $24.15 million. AFX subsequently suspended bridging services and initiated incident response procedures.
The stolen funds have been transferred to Ethereum.
AFX stated that the specific attack path is still under investigation. On-chain security firm PeckShield reported that the attackers transferred the stolen USDC across chains to Ethereum and exchanged it for 12,468 ETH; the funds are currently concentrated in a single address.
The platform stated that the impact is currently limited to AFX's self-operated custody bridges; the trading infrastructure, mainnet system, and the Arbitrum network itself are unaffected. AFX also stated that it is working with ecosystem partners and security agencies to track asset flows.
Arbitrum clarifies that the native bridge is unaffected.
Following the incident, Arbitrum co-founder Steven Goldfeder stated that the Arbitrum native bridge "was not attacked or exploited in any way," and that the unusual transactions originated from a third-party protocol, not from the official network bridging infrastructure.
This statement aims to limit the scope of the incident to a single application layer protocol. If the native bridge malfunctions, the impact usually spreads to the entire Layer 2 network; however, the attack targeted an independent protocol built upon it, making the risk relatively localized.
AFX proposes a return plan to the attackers.
In its public communications, AFX proposed a solution: if the attacker returns 70% of the funds, the remaining 30% can be retained as a "white hat bounty." This practice has become increasingly common in recent crypto security incidents, with some protocols using this tactic to secure a higher percentage of recovered funds.
This incident also reflects the ongoing security pressures facing DeFi in 2026. The report mentions that losses due to attacks in the DeFi sector this year have exceeded $840 million. Just a week earlier, another perpetual contract platform on Arbitrum, Ostium, also lost approximately $18 million due to a compromised oracle key.












