A decentralized exchange built on Arbitrum lost $24 million after an attacker compromised its bridge keys. The exploit hit AFX Trade, a platform that lets users swap assets across chains.
How the Attack Happened
Security firms tracking the incident said the attacker obtained enough hot-validator signatures to authorize a withdrawal of 24.15 million USDC. Hot validators are online signing nodes that approve cross-chain messages. By controlling enough of them, the attacker bypassed the bridge's security checks and drained the funds.
What Was Stolen
The stolen amount — 24.15 million USDC — represents the bulk of the $24 million total. USDC is a stablecoin pegged to the U.S. dollar, so the loss is effectively in cash terms. The attacker moved the funds off the bridge shortly after the withdrawal was approved.
Arbitrum's Position
Arbitrum, the layer-2 network where AFX Trade operates, said its native bridge was not affected. The statement suggests the vulnerability was specific to AFX Trade's custom bridge implementation, not the underlying Arbitrum infrastructure. That distinction matters for users of other Arbitrum-based projects who might worry about a broader security flaw.
The investigation is ongoing. No arrests have been made, and the stolen USDC has not been recovered. AFX Trade has not yet announced a timeline for reimbursing affected users or whether it will attempt to negotiate with the attacker.




