Crypto

AFX Trade says USDC bridge exploit drained about $24 million

The Arbitrum-based perpetuals exchange halted its bridge and offered the attacker 30% of the funds if the rest is returned.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 3 min read

AFX Trade says USDC bridge exploit drained about $24 million
Photo: Decrypt

AFX Trade, a decentralized exchange for perpetual futures on Arbitrum, lost about $24 million after an exploit hit a USDC bridge run by the protocol, according to security firm Blockaid. For everyday DeFi users, the key distinction is that AFX and Arbitrum say the incident involved AFX’s own bridge, not Arbitrum’s native bridge.

Perpetuals are derivative contracts that let traders bet on price moves without an expiration date. A bridge is software that moves crypto between blockchains or related networks, and it can become a high-value target because it often controls assets while transfers are being processed.

Blockaid said Wednesday that the exploit drained $24.15 million from AFX Trade. AFX said on X that it was aware of an incident involving its USDC custody bridge on Arbitrum, had suspended bridge operations, and had started its incident response process while its engineering and security teams investigate the root cause.

AFX has also offered the attacker a deal: return 70% of the funds and keep 30% as a white-hat bounty, according to the protocol. In crypto security, a white-hat bounty is a payment made to someone who identifies or discloses a vulnerability, though in this case the offer came after funds had already been taken.

Where the funds went

Blockchain security firm PeckShield said the stolen USDC was moved from Arbitrum to Ethereum and exchanged for 12,468 ETH. PeckShield said the ETH was sitting in a single wallet.

AFX said the exact attack method remains under investigation. The protocol described the affected system as an AFX-operated USDC custody bridge, which means the reported breach centered on infrastructure controlled by AFX rather than a general failure of the Arbitrum network.

Arbitrum co-founder Steven Goldfeder addressed that point directly on X, saying Arbitrum’s native bridge had not been hacked or exploited. Goldfeder said the transaction came from a third-party protocol.

That distinction matters because Arbitrum is a layer-2 network, a blockchain built to process Ethereum-linked transactions more cheaply or quickly. If a third-party app on Arbitrum is exploited, users of that app may be affected, while the underlying network and its own bridge can remain separate from the incident.

What AFX has confirmed

  • AFX said the incident involved its USDC custody bridge on Arbitrum.
  • The protocol said it suspended bridge operations after detecting the incident.
  • AFX said its teams are still investigating the root cause.
  • Blockaid said the exploit drained $24.15 million.
  • PeckShield said the funds were bridged to Ethereum and swapped for 12,468 ETH.

AFX has not yet publicly identified the attack vector. Until the investigation is complete, the available details point to a protocol-level bridge exploit with funds consolidated on Ethereum, while Arbitrum’s co-founder has said the network’s own bridge was not compromised.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto