AFX Trade Loses $24 Million After Bridge Key Compromise
Offchain Labs says the native Arbitrum bridge was not affected; the attack hit validator signing keys and once again put the risks of cross-chain bridges in DeFi in the spotlight.

Key Takeaways
- AFX Trade lost about $24.15 million on Wednesday after an attacker compromised validator signing keys for an Arbitrum bridge.
- According to Blockaid, the withdrawal of 24,150,000 USDC was validly approved by five hot-validator signatures and released after 200 seconds.
- The attack came as AFX trading volume was surging, while cross-chain bridges are once again being highlighted as a weak point in DeFi.
AFX Trade was hit for about $24.15 million (€21.2 million) on Wednesday after an attacker gained access to the validator signing keys tied to an Arbitrum bridge. On-chain data shows the funds were withdrawn in USDC, while Offchain Labs said the native Arbitrum bridge itself was not hacked or misused.
Bridge Approved the Withdrawal
Security firm Blockaid reported that the bridge’s on-chain rules were never broken. Instead, five hot-validator signatures authorized the withdrawal of 24,150,000 USDC, which was enough to reach the required quorum of roughly two-thirds. Once that happened, the contract accepted the transaction as valid and released the funds after a 200-second dispute window.
That makes this incident different from a typical smart contract exploit. The bridge appears to have worked as designed, but the keys used to approve the withdrawal seem to have been compromised. The stolen USDC was then swapped on Ethereum into about 12,467 ETH, worth roughly $24 million (€21 million), and on-chain trackers now show the assets sitting in one wallet.
Growth Coincided With the Attack
The timing is notable. AFX trading activity had been climbing sharply before the attack. According to DefiLlama, daily perpetuals volume reached its highest level in months in mid-July, as the protocol attracted more users and, with them, more deposits. The amount stolen was nearly the entire total value locked in the protocol.
For European crypto readers, the bigger takeaway is that cross-chain bridges have long been one of DeFi’s weakest points. They often move large sums while depending on a small set of validators or approval signals, so if access keys are compromised, the security of the whole system can unravel quickly. Arbitrum has already dealt with a separate security issue earlier this year involving the L1 Timelock Contract, which showed that risks can extend beyond a network’s core layer. In another Arbitrum-related attack, a compromised key was also enough to drain a large amount, as seen with Ostium.
More Pressure on DeFi Security
The incident adds to a difficult stretch for crypto security overall. In the second quarter, losses from hacks were among the highest on record, and other Arbitrum-linked protocols have also been targeted recently, including an oracle exploit at RWA platform Ostium. The AFX case also fits a familiar pattern: attackers did not need to break the contract itself, only to use long-term access privileges to move funds out.