AFX protocol bridge attacked on Arbitrum, about 24.15 million USDC stolen

AFX protocol bridge attacked on Arbitrum, about 24.15 million USDC stolen

AFX offered the attacker a 30% bounty to return 70% of roughly $24 million stolen after validator-key compromise at its third-party Arbitrum bridge, with the proposal posted on X and sent on-chain.

ETH
USDC
ARB

Fact Check
The primary source (Blockaid announcement) directly confirms an exploit targeting @AFX_XYZ on Arbitrum via its bridge with approximately 24.15M USDC drained, and that Blockaid is working with Arbitrum to contain funds. The Steven Goldfeder post confirms the Arbitrum native bridge was not exploited and the incident originated from a third-party protocol. The time discrepancy (5:30 Beijing time July 23 vs 21:30 UTC July 22) is consistent given the 8-hour offset. Two independent news outlets (Odaily, PANews) corroborate all details.
Summary

AFX Trade lost about $24.15 million in USDC on July 22 after an attacker compromised validator signing keys tied to the protocol’s third-party bridge on Arbitrum, moved the funds to Ethereum and swapped them for about 12,467 ETH. AFX later proposed a white-hat negotiation under which the attacker could keep 30% of the stolen funds, or roughly $7.2 million, if 70% is returned; the offer was published on X and sent to the attacker’s wallet via an on-chain message. The incident did not involve Arbitrum’s native bridge or core network infrastructure, and Blockaid said July 2026 hack losses had reached nearly $97 million.

Terms & Concepts
  • validator signing keys: Cryptographic keys used by bridge validators to approve transfers or other actions; if compromised, attackers may be able to authorize unauthorized withdrawals.
  • third-party bridge: A bridge run by an application or protocol rather than a blockchain network’s native bridge infrastructure.
  • white-hat negotiation: Talks offering a bounty for returned stolen funds, typically to encourage an attacker to return assets in exchange for being treated as a security researcher.