DeFi

AFX Trade Perp DEX on Arbitrum Loses $24M in Bridge Exploit, Offers Attacker 30% Bounty to Return Funds

AFX Trade's Arbitrum-based perp DEX lost $24.15 million after an attacker exploited a USDC custody bridge the protocol operates, quickly converting the haul into 12,468 ETH before AFX offered a 30% white hat bounty to retrieve the rest.

⏱ 2 min read DeFi
Quick Summary
  • AFX Trade lost $24.15 million when an attacker exploited a USDC custody bridge the protocol operates, converting the funds to 12,468 ETH on Ethereum
  • Arbitrum co-founder Steven Goldfeder confirmed the network's own native bridge was not compromised, limiting systemic risk to the layer-2
  • AFX offered the attacker a 30% white hat bounty to return 70% of the stolen funds, echoing a similar plea made by Drift Protocol after its $285 million April hack

AFX Trade, a decentralized perpetuals exchange built on Arbitrum that settles positions in USDC, was drained of $24.15 million on Wednesday after an attacker exploited a custody bridge the protocol itself operates, according to security firm Blockaid.

What Happened

The attacker targeted the AFX-operated USDC custody bridge, not the Arbitrum network itself. On-chain tracking firm PeckShield confirmed the stolen USDC was bridged to Ethereum and swapped for 12,468 ETH, with the full amount parked in a single wallet.

AFX acknowledged the incident publicly, stating its engineering and security teams were ‘actively investigating the root’ cause and that the exact attack vector remains under investigation. The protocol immediately suspended bridge operations after detecting the breach.

Arbitrum Distances Itself

Arbitrum co-founder Steven Goldfeder moved quickly to clarify the scope of the incident, saying the network’s native bridge ‘has not been hacked or exploited in any way’ and that the transaction originated from a third-party protocol. A compromise of Arbitrum’s own bridge would have carried systemic risk across the entire layer-2 ecosystem, whereas a compromised application built on top of it is a contained failure.

AFX confirmed the damage appeared ‘isolated to the AFX-operated custody bridge,’ with neither its trading infrastructure, mainnet, nor the Arbitrum network itself affected.

Bounty Offer

Hours after the exploit, AFX head of growth Ken C publicly offered the attacker a deal: return 70% of the stolen funds and keep the remaining 30% as a ‘white hat bounty.’ The tactic mirrors a pattern seen across major DeFi incidents. Solana-based perpetuals venue Drift Protocol made a similar public appeal following its $285 million hack in April.

Broader Context

The AFX breach adds to what has been a damaging year for DeFi, which has now lost more than $840 million to exploits in 2026. The timing is particularly pointed for the Arbitrum ecosystem: fellow Arbitrum perpetuals platform Ostium was drained of $18 million just one week earlier through a compromised oracle key.

AFX said it is working with ecosystem partners and security firms to trace the stolen assets. The protocol has not confirmed whether the attacker has responded to the bounty offer.

⚖️ Our Verdict 📉 Bearish Signal

A $24 million bridge exploit with the stolen funds already converted to ETH and sitting in a single wallet is a clear negative, and the second Arbitrum-ecosystem perp venue drained in a week after Ostium's $18 million oracle hack. The mitigants: the breach was isolated to a bridge AFX operates rather than Arbitrum's native infrastructure, so the layer-2 itself is unaffected, and AFX has suspended the bridge and is working with security firms to trace the assets. Whether any of it returns now depends on a bounty offer the attacker has not answered.