Loading market data...

AFX Trade's Arbitrum Bridge Drained of $24M in Private Key Attack

AFX Trade's Arbitrum Bridge Drained of $24M in Private Key Attack

AFX Trade's cross-chain bridge on Arbitrum was hit by an exploit on July 22, losing roughly $24.15 million in USDC. The attacker compromised private keys belonging to bridge validators, then used five hot-validator signatures to approve a withdrawal after a roughly 200-second dispute window. Blockaid flagged the exploit at 21:30 UTC that evening. The bridge held about $24.18 million in total value locked just before the incident — meaning the attacker drained nearly everything.

How the exploit worked

This wasn't a bug in the bridge's smart contracts. The attacker got hold of enough hot-validator private keys to meet the threshold for signing off on a withdrawal. The bridge's dispute window — the time between a withdrawal request and final approval — was set at about 200 seconds. That gave the attacker a narrow but sufficient window to push through the transaction before any monitoring system could react. The stolen funds were bridged to Ethereum and swapped for roughly 12,467.5 ETH. The attacker's wallet is known: 0x6276…ebAC.

The white-hat offer

AFX suspended bridge operations shortly after the attack. The team then put out a white-hat deal: return 70% of the funds, keep the remaining 30% as a bounty. No response from the exploiter has been reported as of July 26. The offer is a common play in crypto heists — give the attacker a financial incentive to give most of the money back rather than try to launder it all.

Bridge security trade-offs

The incident highlights the perennial tension in bridge design. Larger validator sets make it harder for an attacker to gather enough signatures, but they slow down operations. Short dispute windows reduce friction for users but compress the time available to catch a malicious withdrawal. Key custody is another weak point: if private keys are stored on hot infrastructure, a single compromise can undo the whole system. AFX's bridge used a threshold-signature model with five validators — a setup that's fast but leaves little room for error if keys are stolen.

The bridge remains suspended. There's no timeline for reopening, and no word on whether AFX will cover user losses from its own treasury. The attacker's ETH hasn't moved since the swap.