AFX Trade drained of $24M, offers hacker 30% bounty to return stolen funds
The Arbitrum-based perpetuals DEX lost $24.15 million in USDC after an attacker compromised validator signing keys for its bridge, then swapped the haul for roughly 12,467 ETH.
AFX Trade, a decentralized perpetuals exchange built on Arbitrum, got cleaned out to the tune of $24.15 million on July 22. The attacker compromised validator signing keys for the platform’s bridge, drained USDC from the protocol, bridged it all to Ethereum, and promptly swapped it for approximately 12,467 ETH at an average price of around $1,937 per token.
The platform’s response? A public offer to let the hacker keep 30% of the stolen funds, roughly $7.2 million, if they return the remaining 70%.
What happened and how the exploit worked
The attack targeted a third-party bridge operated by AFX Trade, not Arbitrum’s native bridge infrastructure. Arbitrum itself wasn’t breached, and its core bridging mechanism remains intact. The vulnerability lived in the layer AFX maintained on top of it.
The attacker gained access to validator signing keys for the AFX-operated bridge, which meant they could move funds out without restriction. The $24.15 million in USDC was bridged from Arbitrum to Ethereum and converted into ETH.
The exploit follows a familiar playbook. A similar attack hit the Verus-Ethereum bridge back in May 2026, using a comparable method to drain funds.
Security firm Blockaid flagged the AFX Trade exploit as part of a broader cluster of attacks it labeled “Hackers Day.” Total losses from hacks during July 2026 have reached nearly $97 million.
The 30% bounty gambit
AFX Trade’s decision to publicly offer the attacker a 30% bounty is increasingly standard practice in crypto exploits. The logic is straightforward: recovering 70% of stolen funds is better than recovering nothing, and on-chain forensics make it increasingly difficult to launder large sums without eventually being identified.
A growing pattern of bridge exploits
Bridge attacks have been the single most lucrative attack vector in DeFi for several years running. The reason is structural: bridges hold large pools of locked assets and rely on validator sets or multisig arrangements that create concentrated points of failure.
The AFX Trade incident fits neatly into this pattern. A third-party bridge, maintained by the protocol team rather than the underlying Layer 2 network, proved to be the weak link.
The nearly $97 million in total July 2026 hack losses, as tracked by Blockaid, suggests the problem is getting worse, not better.
What this means for investors
For traders using perpetual DEXs on Layer 2 networks, the AFX Trade exploit is a concrete reminder to evaluate the infrastructure underneath the trading interface. The exchange itself might have solid smart contracts for its perps engine, but if the bridge it relies on has centralized validator keys, none of that matters when the keys get compromised.