
AFX suffered a USDC loss of $24.15 million after an attacker targeted a cross-chain bridge linked to the trading protocol on July 22.
Summary
- AFX’s cross-chain bridge lost $24.15 million USDC while Arbitrum’s native bridge remains unaffected during the attack.
- The exploiter transferred the stolen USDC to Ethereum and then converted the proceeds into 12,467.5 ETH.
- Security companies trace the stolen funds while AFX and Arbitrum teams investigate the breach.
The incident sparked an investigation by Blockaid and the Arbitrum team, while on-chain trackers followed the stolen funds back to Ethereum.
The attack did not affect Arbitrum’s home bridge. AFX operates its own Sovereign Layer 1 for perpetual trading, but accepts USDC deposits through Arbitrum. The infrastructure affected was a third-party bridge operated by AFX rather than Arbitrum’s main bridge.
AFX Bridge Loses $24.15 Million USDC
Blockaid said it detected the exploit at 9:30 p.m. UTC on July 22. The company said the attack targeted a bridge operated by AFX and drained approximately 24.15 million USDC. An Arbiscan record shows a successful transfer of 24,150,000 USDC from the bridge contract to the recipient’s address at 9:30:25 PM UTC.
The security company said it was working with the Arbitrum team to respond, contact the relevant protocol and help contain the stolen funds. Based on public updates reviewed at the time of publication, no recovery has been confirmed.
AFX has also not released a verified technical post-mortem explaining how the attacker obtained permission to withdraw the funds. The protocol had not announced a recovery plan.
Offchain Labs co-founder Steven Goldfeder confirmed that the suspicious transaction originated from a third-party protocol. It also separated the AFX incident from Arbitrum’s own bridge infrastructure.
“We are aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol and that Arbitrum’s native bridge was not hacked or exploited in any way,” Goldfeder said.
He added that the team would coordinate with the third-party protocol and share more details when they become available.
AFX uses Arbitrum as a route for USDC deposits while running its trading system on a dedicated Layer 1. AFX describes itself as a decentralized derivatives platform built around a sovereign execution environment. A recent protocol post also indicated that users could deposit USDC from Arbitrum before accessing its perpetual markets.
Exploiter converts stolen USDC into ETH
PeckShield said the attacker moved the stolen USDC from Arbitrum to Ethereum and converted the proceeds into 12,467.5 ETH. Lookonchain separately reported that the operator purchased approximately 12,467 ETH at an average price near $1,937 per ETH after transferring the funds.
The conversion moved the stolen value from a US dollar-pegged stablecoin to Ether, exposing the holdings to ETH price movements. Security teams continued to trace the funds after the exchange. At the time of publication, the sources reviewed did not confirm that Circle had frozen USDC before the conversion or that any of the ETH had been recovered.
The attack adds to several security incidents linked to bridges this year. As crypto.news previously reported, Stake DAO shut down its vsdCRV bridge after an unauthorized strike on Arbitrum in May. The project said it had secured mainnet support for the token and limited the incident to the affected bridge.
Earlier in April, a larger exploit hit Kelp DAO’s LayerZero-powered bridge. The attackers drained approximately 116,500 rsETH, worth approximately $292 million. Arbitrum then froze over 30,000 ETH linked to this attacker after the funds were transferred to Arbitrum One.
Investigation focuses on infrastructure operated by AFX
The investigation is now focusing on the bridge operated by AFX and the authorization process behind the withdrawal of 24.15 million USDC. The confirmed transaction shows that the bridge contract has completed the transfer, but public statements do not yet establish the verified root cause. A full post-mortem can determine whether the incident involved compromised validator credentials, faulty access controls, or another weakness.
The main point confirmed is that the exploit affected infrastructure operated by AFX rather than the native Arbitrum bridge. Both Blockaid and Offchain Labs made this separation clear in their initial responses. The Arbitrum network continued to operate and reports reviewed showed no loss of its native bridge.
The incident also draws attention to AFX’s depository infrastructure. The protocol promoted Arbitrum USDC deposits as an entry route into its trading platform. Any changes to deposits, withdrawals or bridge operations will depend on the protocol response and ongoing investigation.
The case continues to develop. The confirmed loss amounts to approximately $24.15 million in USDC, while on-chain trackers have traced the stolen value back to approximately 12,467 ETH on Ethereum. Further updates are expected from AFX, Blockaid and the Arbitrum team as they investigate the breach and track the attacker’s funds.


