AFX Trade, a decentralized perpetuals exchange operating on the Arbitrum blockchain and settling trades in USDC, suffered a major exploit on Wednesday. An attacker managed to drain approximat
AFX Trade, a decentralized perpetuals exchange operating on the Arbitrum blockchain and settling trades in USDC, suffered a major exploit on Wednesday. An attacker managed to drain approximately $24.15 million by targeting the platform’s custody bridge.
Details of the Breach
AFX Trade is known for offering perpetual trading services managed via smart contracts, allowing traders to gain leveraged exposure to various cryptocurrency assets. The exploited bridge serves as a component for moving funds between Arbitrum and Ethereum, facilitating cross-chain access for its users.
Rather than exploiting a flaw in a smart contract, the attacker utilized hot-validator signatures tied to the custody bridge. According to Vladimir S., security chief at Legalblock, five validator signatures approved the withdrawal, surpassing the two-thirds approval threshold required by the bridge protocol. After a 200-second dispute window elapsed without challenge, the contract released the funds as intended.
PeckShield, a blockchain security firm, reported that the attacker transferred the stolen USDC to Ethereum and swapped it for roughly 12,467 ETH, which remains consolidated in a single wallet.
Mini dictionary: Hot-validator signatures, digital signatures generated by bridge validators tasked with approving transactions; “hot” implies continuous online access, which potentially exposes keys to greater risk compared to “cold” offline storage. The security of such bridges relies on multi-signature schemes, where compromise of a quorum can lead to asset loss.
Bridge Security and Response
Steven Goldfeder, co-founder of Offchain Labs, the developer behind Arbitrum, clarified that the native Arbitrum bridge remained secure and had not suffered any breach or exploit.
Steven Goldfeder, co-founder of Offchain Labs, emphasized that the incident affected an external bridge whose validators approved the withdrawal, and not the core Arbitrum infrastructure.
Security experts pointed out that this exploit continues the trend seen throughout 2026, where attackers opt to compromise off-chain elements like private keys and signature authorities, rather than directly targeting smart contract vulnerabilities.
Recent Security Challenges for Arbitrum Protocols
Earlier in April, Drift Protocol lost around $285 million after attackers gradually gained privileged access. Just last week, an oracle attack drained $18 million from Ostium, another Arbitrum-based protocol. These incidents highlight the evolving tactics of attackers seeking to exploit the weakest links in DeFi’s security architecture.
In response to recent exploits, the Arbitrum Security Council, a body responsible for safeguarding network integrity, took the rare step of freezing $71 million in ETH related to the Kelp DAO bridge compromise. This action led to debate about the extent of emergency powers in networks that market themselves as decentralized.
In the AFX Trade case, the attacker quickly bridged funds to Ethereum and swapped the proceeds, potentially making asset recovery even more challenging and further distancing the funds from protocol control.
ProtocolDate of ExploitMethodLoss (USD)AFX TradeJune 2026Bridge validator compromise$24.15 millionDrift ProtocolApril 2026Privileged access (private key)$285 millionOstiumMay 2026Oracle manipulation$18 million
Recent events have led to renewed scrutiny of cross-chain infrastructure’s security, and the ability of DeFi networks to respond to increasingly sophisticated attack vectors.
Repeated incidents have fueled ongoing debate about the trade-offs between decentralization and emergency protocol intervention as Arbitrum-based platforms seek to balance user security with network autonomy.
The post AFX Trade loses $24 million in Arbitrum bridge exploit, attacker swaps funds for 12,467 ETH appeared first on COINTURK NEWS.