AFX Trade Hack: Arbitrum Perp DEX Loses $24M as Bridge Keys Are Compromised

Barely a week after the Ostium oracle exploit hit Arbitrum, another perpetuals DEX on the same network was drained. On July 22, 2026, AFX Trade lost roughly $24.15 million USDC after an attacker compromised the validator signing keys behind a bridge the protocol operates. The stolen funds were moved to Ethereum and swapped for around 12,467 ETH — nearly emptying the platform's total value locked.
Once again, the weak point wasn't the smart contract code. It was the off-chain infrastructure sitting around it, and in this case a bridge that AFX ran itself rather than Arbitrum's native one.
What happened to AFX Trade?
Security firm Blockaid flagged the exploit at 21:30 UTC on July 22. The attacker gained control of the validator signing keys for AFX's USDC custody bridge — the component that authorizes cross-chain withdrawals. With enough signatures to meet the bridge's quorum, the malicious withdrawal looked entirely legitimate to the system.
That detail matters: Blockaid noted the on-chain logic worked exactly as designed. Five hot-validator signatures met the threshold needed to approve the transfer, so the contract released the funds without any bug being triggered. The problem was that the keys producing those signatures were in the wrong hands.
… Continue reading the full article at the original source below.


