AFX Trade hit by Arbitrum custody bridge exploit, loses $24.15M in USDC
AI Market Summary
AFX Trade lost ~\u002224.15M\u0022 USDC after an exploit of its third-party custody bridge on Arbitrum, with funds rapidly bridged to Ethereum and swapped into ETH, complicating recovery. While Arbitrum\u0027s native bridge and core infrastructure were not impacted, the incident reinforces persistent security risk in third-party cross-chain bridges. Public wallet attribution may constrain laundering, but near-term risk sentiment typically deteriorates for connected protocols.
Impact level
● Medium
Affected assets
ARB/USDT-4.38%
AI Insight · ARB/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
AFX Trade, a decentralized perpetuals exchange for crypto and stocks, said it was exploited via its Arbitrum custody bridge, resulting in an estimated $24.15 million loss in USD Coin (USDC).
On-chain activity shows the attacker swiftly moved the funds off Arbitrum (ARB) to Ethereum (ETH), a step that complicates recovery once assets leave the originating network. The stolen USDC was then swapped for 12,467.44 ETH, valued at roughly $24.16 million, and consolidated into a single Ethereum wallet. After the consolidation, no further large withdrawals were observed.
The attacker's Ethereum address is now public, allowing investigators and blockchain analysts to track any attempts to move or cash out the assets.
AFX said it traced the loss to a specific Ethereum account and immediately halted bridge activity while triggering its incident-response plan. Working with blockchain security partners, the exchange is monitoring for any additional movement of the stolen tokens.
Steven Goldfeder, cofounder of Offchain Labs—the team behind Arbitrum—said the exploit targeted AFX's custody bridge, not Arbitrum's native bridge or the broader network. AFX added that the suspicious transactions originated from a third-party protocol, underscoring that Arbitrum's core infrastructure was not affected.
SlowMist reported that the funds remain in the attacker's wallet, enabling the Crypto Defense Alliance (CDA) and multiple exchanges to watch for future transfers. Zellic, which previously audited the bridge code, has joined the investigation to analyze the attack vector. AFX also said it has extended a white-hat settlement offer while continuing to trace funds and publish verified updates.
The incident adds to a recurring theme in cross-chain security: while Arbitrum's native bridge has not been breached, connected third-party bridge infrastructure can become a point of failure. Similar episodes, including Ostium and Allbridge Core, highlight how attackers increasingly focus on adjacent protocols rather than the underlying networks.
Final Summary: AFX Trade lost $24.15 million after attackers exploited a third-party custody bridge and moved funds from Arbitrum to Ethereum. The episode reinforces ongoing risks in third-party bridge security as cross-chain infrastructure expands.