AFX Trade's Arbitrum Bridge Compromised, $24 Million in USDC Drained via Validator Key Exploit
On July 22, 2026, AFX Trade suffered a loss of $24.15 million after their Arbitrum bridge processed a withdrawal authorized by a quorum of five validator signatures. This single approval, which should have been impossible under proper key stewardship, resulted in the majority of the protocol’s USDC reserves being transferred to an address that the contract itself was programmed to trust. Details | Protocol TVL | Recipient wallet
There was no vulnerability in the smart contract logic; rather, the system’s security model depended entirely on the assumption that a sufficient number of validator keys would never be compromised. On this occasion, five validators, representing a necessary threshold, approved the withdrawal. Confirmation

This event took place just forty-nine days after AFX publicized an audit by Zellic, which noted incomplete test coverage and unresolved issues. The protocol’s design included a 200-second dispute period, but no dispute was raised before the transaction was finalized. Reference
By the time AFX suspended the bridge, the assets had already traveled across both Arbitrum and Ethereum networks and had been exchanged for ETH via Uniswap, now consolidated in a final wallet.
Blockaid was the first to publicly identify the exploit on July 22nd, noting: “Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting AFX, a protocol on Arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far.” Source
Steven Goldfeder, Arbitrum’s co-founder, clarified almost immediately that the affected protocol was not the Arbitrum native bridge: “We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way.” Statement
AFX Trade’s initial public response came three hours after Blockaid’s alert, acknowledging the incident, freezing the bridge, and announcing an investigation, but providing no technical explanation or updated figures. AFX statement
Within an hour, PeckShield traced the stolen USDC as it left Arbitrum, was bridged to Ethereum, and swapped for 12,467.5 ETH, then merged into a single account. Analysis
QuillAudits summarized the chain of responsibility: “The same validator set added at deployment is what signed off on this $24M withdrawal.” They added: “That points to the off-chain signing system being compromised, not the contract itself.” Source
Taylor Monahan revisited the Zellic audit, pointing out gaps like missing test coverage and unresolved acknowledgments, and that auditors were not provided a fully runnable environment. Reference The audit was announced by AFX on June 3, 2026, forty-nine days before the exploit. Audit announcement
Validator Quorum and Systemic Weaknesses
AFX’s bridge architecture relied on off-chain validators to approve withdrawals. Once enough voting power was collected, the contract would process the transaction without further verification. The same validator set, established at launch on May 12, 2026, authorized the July 22 withdrawal. Five validator keys, together controlling 7,142 out of 10,000 possible votes (surpassing the 6,667 threshold), were sufficient. Details
- Bridge Contract: 0xCb3B9A3E5668AFE84DC7A864B36b845dCE062e67
- Validator Addresses:
All of these addresses and the destination wallet have been tagged on Arbiscan as linked to the incident, though this does not imply malicious intent by the validators. As Taylor Monahan observed, this tagging can conflate signers and recipients. Source
The 200-second dispute window, meant to allow for challenge of suspicious withdrawals, was insufficient to prevent this event. Transaction details
The Zellic audit reviewed contract logic and threshold implementation, not the reliability of validator key management. AFX’s documentation clarifies that the audit covered only the bridge contract, not all platform components. Docs
Transaction Path and Fund Movement
The attacker’s activity mirrored standard operations, with the stolen USDC moved in six tranches through a shared router, then swapped for ETH on UniswapX, before being consolidated into a single account.
- Withdrawal Initiation: 0x217c45c1272550e0439e53243f2987b7fb3f58b1d33c222597bbb71851b93f74
- Finalization: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b
- Finalizer: 0x5553EA7Bda594aDE7AFe91D279779a42b2B84208
- Operational Address: 0x32E3200D6E944cd9bD1C8C9865293B07206e7A01
- Loot Wallet: 0x2f2974fAbc54dbA33442261211c06BD20E0FEefc
- Bridging Router: 0xB3FA262d0fB521cc93bE83d87b322b8A23DAf3F0
USDC was burned on Arbitrum and minted on Ethereum to the same address in amounts of 5,895,000; 655,000; 7,500,000; 5,000,000; 5,000,000; and 100,000 USDC. Reference
- Deposit-for-Burn Transactions:
On Ethereum, the attacker exchanged USDC for ETH via eight UniswapX Dutch-auction fills, all handled by a solver labeled Rizzolver:
- Total ETH received: 12,467.43703738
- Significant UniswapX fills:
Subsequently, the attacker moved all ETH to a second wallet: Final consolidation | AFX Trade Exploiter 9 wallet
Over the following days, the funds were dispersed across approximately two dozen addresses, with real value split among them and the remainder left as dust. Analysis
Bounty Offer and Attribution

AFX’s follow-up statement, released less than an hour after the first, referenced SlowMist’s observation that the stolen assets remained in the attacker’s addresses, and that these had been reported to the Crypto Defense Alliance to facilitate exchange-level freezes. AFX update | Crypto Defense Alliance
AFX’s head of growth then publicly offered a 70-30 split to the attacker: if 70% of funds were returned, the remaining 30% would be considered a bounty. Offer This approach, now common following major crypto hacks, is based on the premise that partial recovery is preferable when funds are still traceable. TRM Labs: Bounties
The bounty was ignored. Instead, the ETH was fragmented and scattered across numerous wallets, a pattern consistent with laundering, not negotiation. Tracking
AFX’s exploit was not unique. Just a week earlier, Ostium lost $23.75 million on the same chain due to a manipulated price feed. Ostium exploit
Several days after the AFX hack, zeroShadow and SEAL analysts suggested a connection to UNC4899 (TraderTraitor), a North Korean threat group, citing similarities in gas-funding patterns with the KelpDAO exploit. Analysis The rapid fragmentation of funds into many addresses within a single day resembled professional laundering techniques.
Conclusion
In summary, AFX’s bridge processed a withdrawal after five validators signed off, as per the system’s rules. The protocol, routers, and swap venues all behaved as designed; it was the trust in validator key management that failed. The dispute period was insufficient to prevent the exploit, and the post-incident bounty offer went unanswered as funds were dispersed. Forty-nine days after an audit highlighted untested aspects of the codebase, the validator keys—arguably the riskiest element—were left unchecked.
[Full event trail and forensic references are available in the cited links above.]
Get new scam files the moment we publish them — usually 2–3 emails a week.