AFX Trade, a decentralized finance protocol built on Arbitrum, suffered a major security breach after attackers exploited one of its proprietary bridge contracts, draining approximately $24.15 million in USDC. Blockchain security firm Blockaid detected the exploit and confirmed that the attack targeted a bridge operated by AFX rather than the Arbitrum Layer 2 network itself. The incident ranks among the largest DeFi exploits of the month and once again highlights the security risks associated with cross-chain bridge infrastructure.
Following the exploit, blockchain investigators reported that the attacker bridged the stolen funds from Arbitrum to Ethereum, where they were exchanged for approximately 12,467 ETH worth around $24 million. Steven Goldfeder, CEO of Offchain Labs, quickly clarified that Arbitrum’s native bridge and core protocol were not compromised, emphasizing that the incident originated entirely from a third-party application built on the network.
According to Blockaid, the exploit was isolated to a bridge developed and operated by AFX.
The attack resulted in:
Security teams continue monitoring the attacker’s wallets to determine whether additional funds can be frozen or recovered.
Soon after the exploit became public, Steven Goldfeder addressed growing concerns within the crypto community.
He stated that:
The clarification helped distinguish the attack from vulnerabilities affecting the underlying blockchain infrastructure.
Cross-chain bridges continue to represent one of the most common attack vectors in decentralized finance.
Unlike the underlying blockchain, bridges often involve:
These additional layers create more opportunities for attackers to exploit implementation flaws compared with the core blockchain itself.
The AFX exploit adds to an already expensive month for the digital asset industry.
According to blockchain security trackers:
The growing number of exploits continues to reinforce calls for stronger smart contract auditing and more robust bridge security.
Blockchain analytics firm PeckShield traced the attacker’s activity shortly after the exploit occurred.
Investigators observed:
Because blockchain transactions are publicly visible, investigators will continue monitoring the funds for any movement through exchanges or mixing services.
The incident demonstrates the increasingly important role played by blockchain security firms.
Companies such as Blockaid and PeckShield now provide:
Their rapid alerts often provide developers and ecosystem participants with valuable time to respond before additional losses occur.
Russian President Vladimir Putin has signed a landmark cryptocy law establishing the country's first comprehensive regulatory…
Coinbase has launched 24-hour, five-day-a-week trading for nearly 4,000 U.S. stocks for eligible customers in the United Kingdom, marking another major…
Shaw Walters, founder of Eliza Labs, has declared the project's native ELIZA token "dead" and confirmed that the Eliza…
The Web3 fitness platform Step App has announced it will permanently shut down after four years in…
The Digital Asset Market CLARITY Act is running out of time in the U.S. Senate as lawmakers scramble to…
Cloudflare has unveiled Cloudflare Wallets, a new programmable stablecoin wallet system that allows AI agents to independently pay for…