AFX Trade, an Arbitrum-based decentralized exchange, had $24.15 million in USDC drained from its custody bridge on July 22, 2026. Within hours, the team went public with an unusual proposal: let the attacker keep 30% of the haul, roughly $7.2 million, as a so-called white-hat bounty, in exchange for returning the other 70%.

The offer was posted publicly by Ken C, AFX's head of growth. No private negotiations, no quiet settlement. Just a public appeal to someone who had already moved the funds off-chain and converted them to ETH.

What the attacker actually did

This wasn't a smart contract exploit. The contracts worked exactly as intended. The attacker compromised off-chain validator signing keys, which gave them access to AFX's bridge custody system without ever touching the underlying Arbitrum infrastructure. Security firms Blockaid and PeckShield both confirmed this, and both were clear that Arbitrum's native bridge was completely unaffected.

After draining the $24.15 million in USDC, the attacker moved the funds to Ethereum and swapped them for approximately 12,467 ETH at around $1,937 per token. AFX suspended its bridge immediately after detecting the breach.

The detail worth sitting with: smart contract audits, which most DeFi projects lean on as their primary security signal, would not have caught this. Validator key management sits outside that layer entirely, and it tends to get far less scrutiny from users and investors even though it represents a significant attack surface.

Industry reaction and the wider damage

The AFX hack didn't happen in isolation. July 22 and 23 saw a concentrated wave of attacks across multiple platforms, with combined losses exceeding $35 million over those two days. Zoom out to the full month and July 2026 logged nearly $97 million in hack-related losses, according to data from Blockaid and PeckShield.

The pattern is familiar to anyone watching cross-chain bridge development closely: bridges remain one of the most consistently targeted components in crypto infrastructure, and the attack surface keeps growing as more assets move between chains. AFX's case adds another data point to that record, this time with the added twist of a public bounty negotiation that, as of writing, has no confirmed resolution.

This article is for informational purposes only and does not constitute financial advice. Always do your own research before making any investment decisions.