Roughly $24.15 million in USDC vanished from AFX Trade after an attacker exploited the exchange's Arbitrum custody bridge. Within hours, the stolen funds were out of reach: the hacker moved everything from Arbitrum to Ethereum, then swapped the USDC for 12,467.44 ETH at a near-identical value of $24.16 million. Converting frozen stablecoins into ETH gave the attacker a liquid asset that travels freely across platforms.
All the stolen funds were consolidated into a single Ethereum wallet. Since then, no large withdrawals have been recorded from that address, and it is now publicly identified, letting blockchain analysts and investigators track any future movement. SlowMist confirmed the funds are still sitting there, which gives the Crypto Defense Alliance and several exchanges a window to watch for any transfer attempt.
What AFX did after the breach
AFX traced the origin of the loss to one specific Ethereum account and moved fast to limit further damage. The bridge was suspended immediately after the exploit was discovered, and the exchange activated its incident response plan alongside blockchain security partners. Zellic, the firm that previously audited the bridge code, has rejoined the investigation to identify exactly how the attacker got in. AFX has also put a white hat settlement offer on the table.
Arbitrum co-founder Steven Goldfeder was quick to clarify that the attack hit AFX's own custody bridge, not Arbitrum's native bridge or its broader network. AFX separately confirmed the suspicious transactions originated from a third-party protocol, leaving Arbitrum's core infrastructure untouched.
The same pattern, again
The AFX case fits a familiar script. Attacks like those on Ostium and Allbridge Core showed the same dynamic: the underlying network holds up fine, while the third-party bridge connecting it to other chains becomes the weak point. A few recurring factors tend to show up in these incidents:
- Third-party bridges operate on custom code that may not match the security standard of the native chain
- Cross-chain asset movement makes stolen funds harder to freeze or reverse
- Converting stolen stablecoins to ETH breaks the freeze mechanism issuers can apply to USDC
The lesson is not that Arbitrum or Ethereum are broken. It is that the connective tissue between chains keeps getting targeted, and audits alone are not enough to prevent it. Zellic audited the bridge and the attacker still found a way through.
This article is for informational purposes only and does not constitute financial advice or an investment recommendation.



