The attacker didn't break the contract. The contract worked perfectly. That's what makes the AFX Trade exploit so unsettling: on Wednesday, an unknown actor drained $24.15 million from a decentralized perpetuals exchange built on Arbitrum, not by finding a bug in the code, but by getting hold of the private validator signing keys that authorized withdrawals on a bridge AFX itself operates.
Blockchain security firm Blockaid flagged the incident at 21:30 UTC on July 22. According to their analysis, five of the bridge's hot-validator signatures signed off on moving 24,150,000 USDC to the attacker's wallet. That met the roughly two-thirds quorum the bridge required. A 200-second dispute window passed. The contract, doing exactly what it was designed to do, released the funds.
Where the money went
Speed mattered after that. The stolen USDC was bridged from Arbitrum to Ethereum and swapped for approximately 12,468 ETH, worth around $24 million at the time of conversion, all consolidated into a single wallet. PeckShield, which tracked the movement on-chain, confirmed the consolidation. That ETH is now sitting there, visible to anyone watching.
The timing was particularly painful for AFX. According to DefiLlama data cited by CoinDesk, the $24.15 million drained represented nearly the entirety of the protocol's total value locked. The attacker hit at close to the worst possible moment: AFX had been recording multi-month highs in daily perpetuals volume through mid-July, meaning more capital was parked in the protocol than usual.
Arbitrum co-founder Steven Goldfeder was quick to draw a line between AFX's bridge and the underlying network. The Arbitrum native bridge, he stated, "has not been hacked or exploited in any way." The vulnerability was entirely within AFX's own custody infrastructure, a distinction that matters for the broader ecosystem but offers cold comfort to anyone who had funds in the protocol.
AFX suspended the compromised bridge immediately after the exploit was detected. The team then put a public offer on the table: return 70% of the stolen funds and keep the remaining 30%, framed as a white hat bounty. That works out to roughly $7.2 million the attacker could walk away with, no questions asked. Whether that's enough of an incentive, given that 12,468 ETH is already sitting in a wallet the team can't touch, remains to be seen. Blockaid and PeckShield are both actively tracing the assets while the exact method used to compromise the signing keys is still under investigation.
This article is for informational purposes only and does not constitute financial advice or a recommendation to buy, sell, or hold any asset.



