Morning Edition · Thursday, July 23, 2026Published at 1:28 AM EDT · New York
AFX Trade Bridge on Arbitrum Loses $24.15 Million After Validator Signatures Are Compromised
The attacker moved the stolen USD Coin from Arbitrum to Ethereum and swapped it for 12,467 Ether, while Arbitrum said its native bridge was not the point of failure.

AFX Trade, a decentralized perpetual-futures venue built on the Ethereum layer-2 network Arbitrum, lost roughly $24.15 million on Wednesday after an attacker drained one of the cross-chain bridges the protocol operates, according to the security firm Blockaid and reporting by CoinDesk.
The mechanism was not a smart-contract logic flaw but a control-of-keys failure. Investigators said the attacker held enough of the bridge's hot-validator signatures to authorize a single 24.15 million USD Coin (USDC) withdrawal. In practice, that means the multi-signature threshold protecting the bridge was met by keys the attacker controlled, so the contract executed the transfer as designed. The stolen USDC was then bridged from Arbitrum to Ethereum and swapped for 12,467 Ether, a standard laundering step that converts a freezable, issuer-controlled stablecoin into a harder-to-freeze asset.
Offchain Labs co-founder Steven Goldfeder said the Arbitrum native bridge was not hacked or exploited, stressing that the compromised component was a separate bridge that AFX itself runs. That distinction matters. The security of a layer-2's canonical bridge is a systemic property, while a single application's bridge is an isolated counterparty risk. AFX, Blockaid and Arbitrum teams are tracing the funds, and no recovery or attribution had been confirmed at publication.
The loss follows a pattern the desk has tracked closely. Bridges concentrate value and depend on a small set of signing keys, which makes signature or key compromise, rather than reentrancy or oracle manipulation, the recurring root cause of the largest decentralized finance (DeFi) drains.
- If true, who benefits
Offchain Labs and Arbitrum, whose insistence that the native canonical bridge was untouched protects the layer-2's systemic-security reputation and the ARB token by confining blame to a single application's own signing setup.
- The nuance
The $24.15 million drain and the swap into 12,467 Ether are confirmed, but the load-bearing nuance is unresolved: no party has established whether the validator signatures were stolen by an external intruder or misused by an insider, and Arbitrum's technically accurate distancing is also self-interested.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The exposed party is anyone who held funds in or routed through AFX's bridge, and the channel is the gap between a marketed "decentralized" venue and a bridge secured by a handful of hot keys. When a threshold of validator signatures sits on internet-connected machines, the security model is operational key management, not cryptographic decentralization. The rapid swap into Ether also shows the limit of stablecoin freeze tooling. Issuers can blacklist USDC addresses, but only before funds are converted.
What to watch
- Whether AFX or on-chain analytics firms attribute the theft to a specific group or an insider, which would signal whether this was external intrusion or key mishandling.
- Any move by Tether or Circle to freeze linked addresses, and whether the 12,467 Ether is laundered through mixers or centralized exchanges where it can be seized.
- Whether other Arbitrum-based apps running their own bridges disclose the signing setups they use, a direct test of how much "decentralized" branding survives scrutiny.
Observations to monitor, not financial advice.
Synthesized from: CoinDesk · Polylog editors · The Block
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
More from this edition
- Revised CLARITY Act Would Bar the President and Officials From Issuing Crypto Until 2029
- Ethereum Researchers Argue Coordination Design, Not Scaling, Is Crypto's Last Binding Constraint
- Privacy Layer-2s Ship Live Networks as Aztec and Miden Push Confidential Execution
- Galaxy Commits $5 Million to Accelerate Bitcoin's Migration Ahead of Quantum Risk
- SEC's Peirce Warns On-Chain Lending and Crypto Vaults May Fall Under Securities Law
- Zilliqa Halts Native Transfers After Ledger App Flaw Exposes Private Keys
- Physical Coercion Attacks on Crypto Holders Reach 52 in First Half as Losses Climb, CertiK Says
- Lightning Labs Launches Wavelength to Let AI Agents Transact on Bitcoin
- Kraken Parent Payward Expands Tokenized Stocks Beyond US Equities With GTN
- Nasdaq-Listed Zhibao Plans to Take 3,500 Bitcoin in $220 Million Financing as Tesla Books Impairment
- MVMT Labs Bankruptcy Lists Under $1 Million in Assets After a $38 Million Raise