$24 million was drained from AFX Trade, a perpetuals decentralized exchange running on Arbitrum, in what the project itself confirmed as a targeted exploit. That figure puts it among the costlier DeFi hacks of the year so far.

Rather than going dark, the team went public with an unusual offer: return 70% of the stolen funds and keep the remaining $7.2 million, no questions asked. Essentially a bug bounty paid in hindsight. Whether the attacker takes the deal is another matter, but the tactic has worked before in DeFi, most notably when Euler Finance recovered the bulk of its $197M loss in 2023 after a similar negotiation played out on-chain.

Details on exactly how the funds were taken are still thin. The project has not published a post-mortem, and independent security researchers have not yet pinpointed the attack vector. What is clear is that the liquidity was gone fast, and the protocol paused operations shortly after. ARB, the native token of the Arbitrum network, slipped about 1.9% in the hours following the news.

For users who had funds on the platform, the wait now is whether that 30% carrot actually brings anything back.

This article is for informational purposes only and does not constitute financial advice.