Offchain Labs’ CEO Steven Goldfeder responded swiftly after a $24.15 million exploit targeted a third-party bridge on the Arbitrum network. The breach didn’t touch Arbitrum’s native bridge, but instead hit AFX Trade, one of its external protocols. This incident has put a spotlight on the key differences in security between native and third-party bridges.

The attack unfolded on July 22 when hackers compromised validator keys for AFX Trade’s bridge, giving them the power to authorize unauthorized withdrawals. Over $24 million in USDC was drained before being swapped for roughly 12,467 ETH, making the trail harder to trace. Goldfeder made it clear that the vulnerability was isolated to the third-party bridge and that Arbitrum’s native bridge wasn’t affected.

Native Bridge vs. Third-Party Risks

The Arbitrum native bridge benefits from the robustness of the entire rollup’s security framework, which itself is anchored to Ethereum’s strong security guarantees. This means the native bridge inherits protections from multiple layers, making it far harder to compromise. Third-party bridges like AFX Trade, however, bring their own security models, validator management, and trust assumptions. These independent systems introduce additional risks that can’t be fully controlled by the Arbitrum core team.

Goldfeder, a Princeton-trained cryptographer, emphasized Offchain Labs’ ongoing dedication to enhancing bridge security through both technical improvements and educating users. They also vet third-party bridges before allowing them to operate within the Arbitrum ecosystem. Still, the AFX Trade incident exposed the limits of these checks when external protocols manage their own keys and validator sets.

This isn’t the first time compromised validator keys have led to multi-million dollar losses in DeFi, but the rapidity of the hackers’ actions moving quickly to swap stolen USDC to ETH shows how high the stakes remain. AFX Trade even offered a white-hat style bounty to the attackers, proposing they return 70% of the funds, keeping the rest as a bug bounty reward. The situation remains fluid as they attempt to recover what they can.

This content is informational only and should not be considered financial advice.