Barely a week after the Ostium oracle exploit hit Arbitrum, another perpetuals DEX on the same network was drained. On July 22, 2026, AFX Trade lost roughly $24.15 million USDC after an attacker compromised the validator signing keys behind a bridge the protocol operates. The stolen funds were moved to Ethereum and swapped for around 12,467 ETH — nearly emptying the platform's total value locked.
Once again, the weak point wasn't the smart contract code. It was the off-chain infrastructure sitting around it, and in this case a bridge that AFX ran itself rather than Arbitrum's native one.
What happened to AFX Trade?
Security firm Blockaid flagged the exploit at 21:30 UTC on July 22. The attacker gained control of the validator signing keys for AFX's USDC custody bridge — the component that authorizes cross-chain withdrawals. With enough signatures to meet the bridge's quorum, the malicious withdrawal looked entirely legitimate to the system.
That detail matters: Blockaid noted the on-chain logic worked exactly as designed. Five hot-validator signatures met the threshold needed to approve the transfer, so the contract rel...


English (US)