AFX Trade loses $24M after validator keys compromised

Editorial illustration for: Arbitrum-based AFX Trade drained of $24 million after validator keys compromised

In brief

  • AFX Trade lost $24.15 million after attackers compromised offchain validator signing keys, not smart contracts.
  • Five bridge validator signatures approved 24.15 million USDC withdrawal, meeting the two-thirds quorum requirement.
  • Stolen USDC was bridged to Ethereum and swapped for approximately 12,467 ETH worth $24 million.
  • Offchain Labs confirmed Arbitrum native bridge was uncompromised; attack originated from third-party protocol.

How the Attack Unfolded

Security firm Blockaid reported that five of the bridge's hot-validator signatures authorized the withdrawal of 24,150,000 USDC, meeting the roughly two-thirds quorum requirement. The on-chain logic itself was not bypassed — instead, the attacker obtained enough private keys to meet the threshold for a legitimate-looking transaction. The attacker then bridged the stolen USDC to Ethereum and swapped it for about 12,467 ETH, worth roughly $24 million.

The roughly $24 million drained was almost the entirety of the protocol's total value locked, meaning the attacker emptied the vault in a single transaction. AFX's trading activity had been climbing sharply in the run-up to the attack, with daily perpetuals volume spiking to multi-month highs in mid-July — making the timing particularly damaging for a platform gaining traction.

Arbitrum Bridge Integrity Intact

Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said the Arbitrum native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol.

The distinction matters. Offchain Labs emphasized that the Arbitrum native bridge's core infrastructure was not compromised. The vulnerability lay in how AFX Trade's own bridge operators or validators stored their signing keys offchain — a common but riskier practice than hardware security modules or multi-sig vaults.

Part of a Larger Pattern

This incident mirrors the roughly $285 million Drift Protocol loss in April, where attackers spent money to gain privileged access rather than exploiting contract vulnerabilities. Most of the hacks and exploits this year have targeted offchain components rather than vulnerabilities in smart contracts themselves. Q2 was among the worst quarters for hacks on record, with a run of Arbitrum-based protocols hit in quick succession. The shift underscores a growing risk: as smart contracts mature, attackers increasingly hunt for operational weak points — key management, validator setup, and third-party integrations.

Frequently asked questions

What was compromised in the AFX Trade attack?

Private validator signing keys held offchain by bridge operators were compromised, not the smart contract itself. The attacker obtained enough keys to meet the two-thirds quorum required to approve the withdrawal.

How much was stolen and where did it go?

Approximately $24.15 million in USDC was withdrawn. The attacker bridged the USDC to Ethereum and swapped it for about 12,467 ETH, worth roughly $24 million.

Was the Arbitrum native bridge hacked?

No. Offchain Labs stated the Arbitrum native bridge has not been hacked or exploited. The attack targeted a third-party protocol's offchain key management, not Arbitrum's infrastructure.