Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    An Update on Integrating Zcash on Ethereum (ZoE)

    July 23, 2026

    Circle partners with Kakao, Toss on South Korea stablecoin push

    July 23, 2026

    Cobie says UpOnly will return if someone buys this $20M NFT

    July 23, 2026
    Facebook X (Twitter) Instagram
    Thursday, July 23
    • About
    • Contact us
    • Privacy Policy
    Facebook X (Twitter) LinkedIn YouTube
    Blockchain Echo
    Banner
    • Lithosphere News Releases
    • Bitcoin
    • Crypto
    • Ethereum
    • Litecoin
    • Altcoins
    • Blockchain
    Blockchain Echo
    Home » AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH
    Crypto

    AFX bridge exploit drains $24.15M USDC as attacker buys 12,467 ETH

    John SmithBy John SmithJuly 23, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    AFX suffered a $24.15 million USDC loss after an attacker targeted a cross-chain bridge linked to the trading protocol on July 22.

    Summary

    • AFX’s cross-chain bridge lost $24.15 million USDC while Arbitrum’s native bridge remained unaffected during attack.
    • The exploiter moved stolen USDC to Ethereum and converted the proceeds into 12,467.5 ETH afterward.
    • Security firms are tracing the stolen funds as AFX and Arbitrum teams investigate the breach.

    The incident triggered an investigation by Blockaid and the Arbitrum team, while on-chain trackers followed the stolen funds to Ethereum.

    The attack did not affect Arbitrum’s native bridge. AFX operates its own sovereign Layer 1 for perpetual trading but accepts USDC deposits through Arbitrum. The affected infrastructure was a third-party bridge operated by AFX rather than Arbitrum’s core bridge.

    AFX bridge loses $24.15 million USDC

    Blockaid said it detected the exploit at 9:30 p.m. UTC on July 22. The firm said the attack targeted a bridge operated by AFX and drained about 24.15 million USDC. An Arbiscan record shows a successful transfer of 24,150,000 USDC from the bridge contract to the recipient address at 9:30:25 p.m. UTC.

    Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.

    Our team has been working with the incredible folks on… https://t.co/0Qd9ve5gPB

    — Blockaid (@blockaid_) July 22, 2026

    The security firm said it was working with the Arbitrum team to respond, contact the affected protocol and help contain the stolen funds. Based on the public updates reviewed at publication time, no recovery had been confirmed. 

    AFX had also not published a verified technical postmortem explaining how the attacker gained authorization to withdraw the funds. The protocol had not announced a recovery plan.

    Offchain Labs co-founder Steven Goldfeder confirmed that the suspicious transaction came from a third-party protocol. He also separated the AFX incident from Arbitrum’s own bridge infrastructure.

    “We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” Goldfeder said. 

    He added that the team would coordinate with the third-party protocol and share more details when available.

    AFX uses Arbitrum as a route for USDC deposits while running its trading system on a dedicated Layer 1. AFX describes itself as a decentralized derivatives platform built around a sovereign execution environment. A recent protocol post also said users could deposit USDC from Arbitrum before accessing its perpetual markets.

    Exploiter converts stolen USDC into ETH

    PeckShield said the attacker moved the stolen USDC from Arbitrum to Ethereum and converted the proceeds into 12,467.5 ETH. Lookonchain separately reported that the exploiter bought about 12,467 ETH at an average price near $1,937 per ETH after moving the funds.

    The conversion moved the stolen value from a U.S. dollar-pegged stablecoin into Ether, exposing the holdings to ETH price movements. Security teams continued tracing the funds after the swap. At publication time, the reviewed sources did not confirm that Circle had frozen the USDC before conversion or that any of the ETH had been recovered.

    The attack adds to several bridge-related security incidents this year. As crypto.news previously reported, Stake DAO closed its vsdCRV bridge after an unauthorized mint on Arbitrum in May. The project said it secured the token’s mainnet backing and contained the incident to the affected bridge.

    Earlier in April, a larger exploit hit Kelp DAO’s LayerZero-powered bridge. Attackers drained roughly 116,500 rsETH worth about $292 million. Arbitrum later froze more than 30,000 ETH linked to that attacker after the funds moved onto Arbitrum One.

    Investigation focuses on AFX-operated infrastructure

    The investigation now centers on the AFX-operated bridge and the authorization process behind the 24.15 million USDC withdrawal. The confirmed transaction shows that the bridge contract finalized the transfer, but public statements do not yet establish the verified root cause. A full postmortem may determine whether the incident involved compromised validator credentials, faulty access controls or another weakness.

    The main confirmed point is that the exploit affected infrastructure operated by AFX rather than Arbitrum’s native bridge. Blockaid and Offchain Labs both made that separation clear in their initial responses. The Arbitrum network continued operating, and reviewed reports showed no loss from its native bridge.

    The incident also places attention on AFX’s deposit infrastructure. The protocol has promoted USDC deposits from Arbitrum as an entry route into its trading platform. Any changes to deposits, withdrawals or bridge operations will depend on the protocol’s response and the ongoing investigation.

    The case remains developing. The confirmed loss stands at about $24.15 million in USDC, while on-chain trackers have traced the stolen value into roughly 12,467 ETH on Ethereum. Further updates are expected from AFX, Blockaid and the Arbitrum team as they review the breach and track the attacker’s funds.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe fine print on the crypto ‘reserves’ of New Hampshire and Arizona
    Next Article Ethereum JS Ecosystem Updates | Ethereum Foundation Blog
    John Smith

    Related Posts

    Circle partners with Kakao, Toss on South Korea stablecoin push

    July 23, 2026

    Crypto vaults could fall under SEC rules, Hester Peirce warns

    July 23, 2026

    UK Treasury races to solve cash barrier before tokenized bond debut

    July 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    HTX prepares for dinner with Donald Trump

    May 24, 2026

    MARA security tops $4.3M as wrench attacks surge

    May 24, 2026

    Bithumb boosts security in wake of SK Telecom malware hack

    May 24, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    About Us

    Stay updated on the world of cryptocurrency
    Your one-stop source for daily crypto news and insights
    Blockchainecho.info: Your trusted daily crypto companion

    Most Popular

    HTX prepares for dinner with Donald Trump

    May 24, 2026

    MARA security tops $4.3M as wrench attacks surge

    May 24, 2026

    Bithumb boosts security in wake of SK Telecom malware hack

    May 24, 2026
    Copyright © 2025
    • Home
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.