AFX Trade, a decentralized finance protocol built on Arbitrum, suffered a major security breach after attackers exploited one of its proprietary bridge contracts, draining approximately $24.15 million in USDC. Blockchain security firm Blockaid detected the exploit and confirmed that the attack targeted a bridge operated by AFX rather than the Arbitrum Layer 2 network itself. The incident ranks among the largest DeFi exploits of the month and once again highlights the security risks associated with cross-chain bridge infrastructure.
Following the exploit, blockchain investigators reported that the attacker bridged the stolen funds from Arbitrum to Ethereum, where they were exchanged for approximately 12,467 ETH worth around $24 million. Steven Goldfeder, CEO of Offchain Labs, quickly clarified that Arbitrum’s native bridge and core protocol were not compromised, emphasizing that the incident originated entirely from a third-party application built on the network.
According to Blockaid, the exploit was isolated to a bridge developed and operated by AFX.
The attack resulted in:
Security teams continue monitoring the attacker’s wallets to determine whether additional funds can be frozen or recovered.
Soon after the exploit became public, Steven Goldfeder addressed growing concerns within the crypto community.
He stated that:
The clarification helped distinguish the attack from vulnerabilities affecting the underlying blockchain infrastructure.
Cross-chain bridges continue to represent one of the most common attack vectors in decentralized finance.
Unlike the underlying blockchain, bridges often involve:
These additional layers create more opportunities for attackers to exploit implementation flaws compared with the core blockchain itself.
The AFX exploit adds to an already expensive month for the digital asset industry.
According to blockchain security trackers:
The growing number of exploits continues to reinforce calls for stronger smart contract auditing and more robust bridge security.
Blockchain analytics firm PeckShield traced the attacker’s activity shortly after the exploit occurred.
Investigators observed:
Because blockchain transactions are publicly visible, investigators will continue monitoring the funds for any movement through exchanges or mixing services.
The incident demonstrates the increasingly important role played by blockchain security firms.
Companies such as Blockaid and PeckShield now provide:
Their rapid alerts often provide developers and ecosystem participants with valuable time to respond before additional losses occur.
The race to bring traditional finance on-chain continues to accelerate after Mubadala Capital, the asset management…
Several key Democratic lawmakers have expressed renewed concerns over the latest draft of the Digital Asset…
BitMEX, one of the most influential cryptocy derivatives exchanges in history, has announced it will…
A newly released draft of the Digital Asset Market CLARITY Act includes a temporary ethics provision that…
S&P Dow Jones Indices and Pantera Capital have launched the new S&P Pantera Digital Asset Index, introducing a fundamentally…
Telegram founder and CEO Pavel Durov has announced that the messaging platform will launch a native non-custodial crypto wallet for…