AFX Trade Loses $24 Million in USDC to a Bridge Exploit on Arbitrum — Here’s What We Know
A bridge exploit drained $24 million in Circle’s USDC stablecoin from AFX Trade, a protocol built on the Arbitrum (ARB) network, late Wednesday. Cybersecurity firm Blockaid detected the attack and disclosed it publicly, identifying the exploit as specific to a bridge AFX operates rather than any vulnerability in Arbitrum’s own infrastructure.
Nearly Every Dollar in the Contract Is Gone
The attacker has reportedly moved the stolen funds from Arbitrum to Ethereum (ETH) and converted them into approximately 12,467 ETH at an average price of $1,937, according to analytics platform Lookonchain.
The AFX bridge contract on Arbitrum held roughly $24.2 million in USDC before the attack — meaning the exploit drained nearly everything locked in the contract.
According to The Defiant’s coverage on the matter, deposits in the bridge had grown from approximately $19.3 million in mid-June, suggesting the contract had been actively accumulating funds in the weeks leading up to the attack.
Steven Goldfeder, co-founder of Offchain Labs — the company behind Arbitrum’s development — addressed the incident in a post on social media.
The exploit originated from a third-party protocol, he said, and Arbitrum’s own native bridge was not touched. “We will coordinate with the third party team and will report more details when we have them,” Goldfeder wrote on X.
We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way.
We will coordinate with the third…
— Steven Goldfeder (@sgoldfed) July 22, 2026
AFX Is the Second Arbitrum Exploit in Two Weeks
The AFX attack is the second significant exploit targeting a protocol built on Arbitrum in less than two weeks. On July 15, perpetuals exchange Ostium halted all trading after an attacker manipulated its oracle system — the price feed mechanism that tells a protocol what assets are worth — to drain between $18 million and $24 million in USDC from its liquidity vault.
That attack was more technically sophisticated, exploiting a compromised oracle signer key to submit falsified price data and trigger artificial trading profits across approximately ten repeated cycles within a single five-minute window.
Blockaid detected that incident as well. The stolen funds from the Ostium attack were subsequently routed through Tornado Cash, a crypto mixing service commonly used by these malicious actors to obscure transaction trails.
Arbitrum had a separate security incident earlier this year, when it froze around $71 million in funds stolen from Kelp DAO following a different exploit.
AFX Trade had not issued a public statement at the time of writing. Blockaid and onchain investigators are continuing to track the exploiter’s wallet. The investigation is ongoing.
Featured image generated with OpenArt.