What to know:
- AFX bridge exploit drained $24.15 million USDC, with funds transferred from Arbitrum bridge contract July 22.
- Attackers converted stolen 24.15 million USDC into 12,467.5 ETH at an average $1,937 per ETH.
- Investigation continues with Blockaid, Offchain Labs, and AFX, while Arbitrum’s native bridge remained unaffected.

The AFX bridge exploit led to the loss of 24.15 million USDC after the attackers attacked the cross-chain bridge connected to AFX’s decentralized perpetual trading platform on July 22. However, the breach targeted infrastructure operated by AFX rather than Arbitrum’s native bridge, prompting an ongoing investigation by Blockaid, Offchain Labs, and the affected protocol while on-chain analysts continued tracing the stolen assets.
Blockaid discovered the exploit at 21:30 UTC as Arbiscan logs showed the transfer of 24,150,000 USDC from the bridge contract to the attacker-controlled address. The firm explained that it worked with Arbitrum and AFX on assessing the situation. Asset recovery had yet to happen, and there was no statement from AFX on what led to the exploit.
A sovereign Layer 1 network for perpetual trading, AFX bridge exploit uses Arbitrum as the entry point for depositing USDC through a third-party bridge. The exploit only affects the third-party bridge and not Arbitrum’s core bridge since it is still operating normally.
Also Read | 67% of Solana Blocks Now Come From Europe, Glassnode Reports
AFX Bridge Exploit Investigation Continues
Co-founder of Offchain Labs, Steven Goldfeder, explained that the suspicious transaction happened from a third-party protocol and not Arbitrum’s native bridge. According to him, the team was working with AFX to investigate it, and more information would be available as the investigation continues.
PeckShield, a blockchain security firm, reported that the attacker moved the stolen USDC to Ethereum from Arbitrum before converting the USDC proceeds into 12,467.5 ETH. Lookonchain noted that it bought at an average price of about $1,937 per ETH, meaning that the stolen funds are now harder to freeze after exiting the stablecoin ecosystem.
Bridge Security Risks Return to Focus
The latest AFX bridge exploit comes after an increasing number of security issues on decentralized finance through cross-chain bridges. Earlier this year, Stake DAO was forced to close its vsdCRV bridge after there was an unauthorized mint on Arbitrum, and Kelp DAO’s LayerZero bridge lost about 116,500 rsETH, which had a value of about $292 million.
For users, the attack reinforces the distinction between the blockchain network and the external application running on it. In this case, it is the AFX bridge infrastructure that suffers from the loss and not the Arbitrum network itself, although the issue can raise questions about cross-chain security protocols and bridge authorization and operation procedures.
Also Read | Hester Peirce Warns Crypto Vaults Could Fall Under US Securities Laws





Be the first to comment