AFX Trade offers exploiter $7.2M bounty to return 70% of stolen funds

AFX Trade offers exploiter $7.2M bounty to return 70% of stolen funds

The Arbitrum-based DEX is trying the diplomatic route after a $24 million bridge exploit drained its custody system through compromised validator keys.

AFX Trade, a decentralized exchange running on Arbitrum, just lost $24.15 million in USDC through a bridge attack. And now it’s essentially negotiating with the person who robbed it, offering them roughly $7.2 million to give the rest back.

The white-hat bounty deal, proposed publicly by AFX head of growth Ken C, would let the attacker keep 30% of the stolen funds as a “bounty” in exchange for returning the remaining 70%.

Advertisement

What actually happened

The exploit hit on July 22, 2026, targeting AFX Trade’s custody bridge rather than its smart contracts or Arbitrum’s underlying infrastructure. The attacker compromised off-chain validator signing keys.

Once inside, the attacker drained approximately $24.15 million in USDC from the bridge. They then moved the funds to Ethereum and swapped them for about 12,467 ETH, which was trading at roughly $1,937 per token at the time. AFX suspended its bridge immediately after discovering the breach.

Security firms Blockaid and PeckShield both confirmed the attack and were quick to note that Arbitrum’s native bridge remained completely unaffected.

Part of a much bigger problem

AFX wasn’t the only victim that week. The exploit was part of a concentrated wave of attacks on July 22 and 23, which collectively resulted in losses exceeding $35 million across multiple platforms. Zoom out further and July 2026 saw nearly $97 million in total hack-related losses, according to data from Blockaid and PeckShield.

The AFX exploit is particularly instructive because it didn’t involve a smart contract flaw. The contracts worked exactly as designed. The weakness was in the off-chain validator key management. Smart contract audits only cover one layer of security. The operational security of key management, validator selection, and bridge architecture often receives far less scrutiny from users, even though it represents a substantial attack surface.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

AFX Trade offers exploiter $7.2M bounty to return 70% of stolen funds

AFX Trade offers exploiter $7.2M bounty to return 70% of stolen funds

The Arbitrum-based DEX is trying the diplomatic route after a $24 million bridge exploit drained its custody system through compromised validator keys.

AFX Trade, a decentralized exchange running on Arbitrum, just lost $24.15 million in USDC through a bridge attack. And now it’s essentially negotiating with the person who robbed it, offering them roughly $7.2 million to give the rest back.

The white-hat bounty deal, proposed publicly by AFX head of growth Ken C, would let the attacker keep 30% of the stolen funds as a “bounty” in exchange for returning the remaining 70%.

Advertisement

What actually happened

The exploit hit on July 22, 2026, targeting AFX Trade’s custody bridge rather than its smart contracts or Arbitrum’s underlying infrastructure. The attacker compromised off-chain validator signing keys.

Once inside, the attacker drained approximately $24.15 million in USDC from the bridge. They then moved the funds to Ethereum and swapped them for about 12,467 ETH, which was trading at roughly $1,937 per token at the time. AFX suspended its bridge immediately after discovering the breach.

Security firms Blockaid and PeckShield both confirmed the attack and were quick to note that Arbitrum’s native bridge remained completely unaffected.

Part of a much bigger problem

AFX wasn’t the only victim that week. The exploit was part of a concentrated wave of attacks on July 22 and 23, which collectively resulted in losses exceeding $35 million across multiple platforms. Zoom out further and July 2026 saw nearly $97 million in total hack-related losses, according to data from Blockaid and PeckShield.

The AFX exploit is particularly instructive because it didn’t involve a smart contract flaw. The contracts worked exactly as designed. The weakness was in the off-chain validator key management. Smart contract audits only cover one layer of security. The operational security of key management, validator selection, and bridge architecture often receives far less scrutiny from users, even though it represents a substantial attack surface.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.