AFX Trade Perpetual Exchange Drained of $24 Million in USDC Bridge Exploit
Quick Look
- AFX Trade, an Arbitrum-based perpetuals exchange, lost $24.15 million in a USDC bridge exploit.
- The protocol halted the bridge and offered the attacker a 30% white hat bounty for returning 70% of the funds, which were swapped for 12,468 ETH.
AI-generated summary
Why It Matters
AFX Trade, a decentralized perpetuals exchange on Arbitrum, suffered a $24.15 million exploit on its USDC custody bridge. The attack vector is under investigation, and the funds were swapped for 12,468 ETH.
AFX Trade, a decentralized perpetuals exchange on Arbitrum that settles in the stablecoin USDC, was drained of $24.15 million on Wednesday in an exploit that hit a bridge the protocol operates, security firm Blockaid said.
In a tweet, AFX said the exact attack vector remains under investigation. The on-chain money trail shows that the attacker bridged the stolen USDC to Ethereum and swapped it for 12,468 ETH, now sitting in a single wallet, PeckShield said.
Arbitrum moved fast to put distance between itself and the protocol. Co-founder Steven Goldfeder said the network's native bridge "has not been hacked or exploited in any way," and that the transaction came from a third-party protocol. A breach of Arbitrum's own bridge would ripple across the entire layer-2; a compromised app sitting on top of it is a contained failure.
AFX suspended bridge operations and said the damage looked "isolated to the AFX-operated custody bridge," noting that neither its trading infrastructure and mainnet, nor the Arbitrum network itself, had been compromised.
The firm added that it was working with ecosystem partners and security firms to trace the stolen assets. Hours later, AFX's head of growth, Ken C, offered the attacker a way out: return 70% of the haul and keep the other 30% as a "white hat bounty." Such public pleas have become a recurring feature of crypto exploits—Solana's Drift Protocol tried the same after its $285 million hack in April.
What to Watch
AI outlook — possibilities, not facts
AFX Trade will continue its investigation into the exploit's exact attack vector.
Very likely · Within days
AFX Trade will continue efforts to recover the stolen funds, potentially through the white hat bounty offer.
Likely · Within weeks
Open Questions
- What was the exact attack vector?
- Will the attacker return the funds for the bounty?
- How will AFX Trade recover from this loss?







