CryptoReal
CASE FILE — Jul 27, 2026

AFX Trade's Arbitrum Bridge Compromised, $24 Million in USDC Drained via Validator Key Exploit

On July 22, 2026, AFX Trade suffered a loss of $24.15 million after their Arbitrum bridge processed a withdrawal authorized by a quorum of five validator signatures. This single approval, which should have been impossible under proper key stewardship, resulted in the majority of the protocol’s USDC reserves being transferred to an address that the contract itself was programmed to trust. Details | Protocol TVL | Recipient wallet

There was no vulnerability in the smart contract logic; rather, the system’s security model depended entirely on the assumption that a sufficient number of validator keys would never be compromised. On this occasion, five validators, representing a necessary threshold, approved the withdrawal. Confirmation

This event took place just forty-nine days after AFX publicized an audit by Zellic, which noted incomplete test coverage and unresolved issues. The protocol’s design included a 200-second dispute period, but no dispute was raised before the transaction was finalized. Reference

By the time AFX suspended the bridge, the assets had already traveled across both Arbitrum and Ethereum networks and had been exchanged for ETH via Uniswap, now consolidated in a final wallet.

Blockaid was the first to publicly identify the exploit on July 22nd, noting: “Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting AFX, a protocol on Arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far.” Source

Steven Goldfeder, Arbitrum’s co-founder, clarified almost immediately that the affected protocol was not the Arbitrum native bridge: “We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way.” Statement

AFX Trade’s initial public response came three hours after Blockaid’s alert, acknowledging the incident, freezing the bridge, and announcing an investigation, but providing no technical explanation or updated figures. AFX statement

Within an hour, PeckShield traced the stolen USDC as it left Arbitrum, was bridged to Ethereum, and swapped for 12,467.5 ETH, then merged into a single account. Analysis

QuillAudits summarized the chain of responsibility: “The same validator set added at deployment is what signed off on this $24M withdrawal.” They added: “That points to the off-chain signing system being compromised, not the contract itself.” Source

Taylor Monahan revisited the Zellic audit, pointing out gaps like missing test coverage and unresolved acknowledgments, and that auditors were not provided a fully runnable environment. Reference The audit was announced by AFX on June 3, 2026, forty-nine days before the exploit. Audit announcement

Validator Quorum and Systemic Weaknesses

AFX’s bridge architecture relied on off-chain validators to approve withdrawals. Once enough voting power was collected, the contract would process the transaction without further verification. The same validator set, established at launch on May 12, 2026, authorized the July 22 withdrawal. Five validator keys, together controlling 7,142 out of 10,000 possible votes (surpassing the 6,667 threshold), were sufficient. Details

All of these addresses and the destination wallet have been tagged on Arbiscan as linked to the incident, though this does not imply malicious intent by the validators. As Taylor Monahan observed, this tagging can conflate signers and recipients. Source

The 200-second dispute window, meant to allow for challenge of suspicious withdrawals, was insufficient to prevent this event. Transaction details

The Zellic audit reviewed contract logic and threshold implementation, not the reliability of validator key management. AFX’s documentation clarifies that the audit covered only the bridge contract, not all platform components. Docs

Sums referenced in this case file

Transaction Path and Fund Movement

The attacker’s activity mirrored standard operations, with the stolen USDC moved in six tranches through a shared router, then swapped for ETH on UniswapX, before being consolidated into a single account.

USDC was burned on Arbitrum and minted on Ethereum to the same address in amounts of 5,895,000; 655,000; 7,500,000; 5,000,000; 5,000,000; and 100,000 USDC. Reference

On Ethereum, the attacker exchanged USDC for ETH via eight UniswapX Dutch-auction fills, all handled by a solver labeled Rizzolver:

Subsequently, the attacker moved all ETH to a second wallet: Final consolidation | AFX Trade Exploiter 9 wallet

Over the following days, the funds were dispersed across approximately two dozen addresses, with real value split among them and the remainder left as dust. Analysis

Bounty Offer and Attribution

AFX’s follow-up statement, released less than an hour after the first, referenced SlowMist’s observation that the stolen assets remained in the attacker’s addresses, and that these had been reported to the Crypto Defense Alliance to facilitate exchange-level freezes. AFX update | Crypto Defense Alliance

AFX’s head of growth then publicly offered a 70-30 split to the attacker: if 70% of funds were returned, the remaining 30% would be considered a bounty. Offer This approach, now common following major crypto hacks, is based on the premise that partial recovery is preferable when funds are still traceable. TRM Labs: Bounties

The bounty was ignored. Instead, the ETH was fragmented and scattered across numerous wallets, a pattern consistent with laundering, not negotiation. Tracking

AFX’s exploit was not unique. Just a week earlier, Ostium lost $23.75 million on the same chain due to a manipulated price feed. Ostium exploit

Several days after the AFX hack, zeroShadow and SEAL analysts suggested a connection to UNC4899 (TraderTraitor), a North Korean threat group, citing similarities in gas-funding patterns with the KelpDAO exploit. Analysis The rapid fragmentation of funds into many addresses within a single day resembled professional laundering techniques.

Conclusion

In summary, AFX’s bridge processed a withdrawal after five validators signed off, as per the system’s rules. The protocol, routers, and swap venues all behaved as designed; it was the trust in validator key management that failed. The dispute period was insufficient to prevent the exploit, and the post-incident bounty offer went unanswered as funds were dispersed. Forty-nine days after an audit highlighted untested aspects of the codebase, the validator keys—arguably the riskiest element—were left unchecked.

[Full event trail and forensic references are available in the cited links above.]


AFX TradeValidator Compromise
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.