AFX Trade, a decentralized perpetuals exchange built on Arbitrum that settles positions in USDC, was drained of $24.15 million on Wednesday after an attacker exploited a custody bridge the protocol itself operates, according to security firm Blockaid.
What Happened
The attacker targeted the AFX-operated USDC custody bridge, not the Arbitrum network itself. On-chain tracking firm PeckShield confirmed the stolen USDC was bridged to Ethereum and swapped for 12,468 ETH, with the full amount parked in a single wallet.
AFX acknowledged the incident publicly, stating its engineering and security teams were ‘actively investigating the root’ cause and that the exact attack vector remains under investigation. The protocol immediately suspended bridge operations after detecting the breach.
Arbitrum Distances Itself
Arbitrum co-founder Steven Goldfeder moved quickly to clarify the scope of the incident, saying the network’s native bridge ‘has not been hacked or exploited in any way’ and that the transaction originated from a third-party protocol. A compromise of Arbitrum’s own bridge would have carried systemic risk across the entire layer-2 ecosystem, whereas a compromised application built on top of it is a contained failure.
AFX confirmed the damage appeared ‘isolated to the AFX-operated custody bridge,’ with neither its trading infrastructure, mainnet, nor the Arbitrum network itself affected.
Bounty Offer
Hours after the exploit, AFX head of growth Ken C publicly offered the attacker a deal: return 70% of the stolen funds and keep the remaining 30% as a ‘white hat bounty.’ The tactic mirrors a pattern seen across major DeFi incidents. Solana-based perpetuals venue Drift Protocol made a similar public appeal following its $285 million hack in April.
Broader Context
The AFX breach adds to what has been a damaging year for DeFi, which has now lost more than $840 million to exploits in 2026. The timing is particularly pointed for the Arbitrum ecosystem: fellow Arbitrum perpetuals platform Ostium was drained of $18 million just one week earlier through a compromised oracle key.
AFX said it is working with ecosystem partners and security firms to trace the stolen assets. The protocol has not confirmed whether the attacker has responded to the bounty offer.


