AFX Trade, a decentralized perpetuals exchange on Arbitrum that settles in the stablecoin USDC, was drained of $24.15 million on Wednesday in an exploit that hit a bridge the protocol operates, security firm Blockaid said.
In a tweet, AFX said the exact attack vector remains under investigation. The on-chain money trail shows that the attacker bridged the stolen USDC to Ethereum and swapped it for 12,468 ETH, now sitting in a single wallet, PeckShield said.
Arbitrum moved fast to put distance between itself and the protocol. Co-founder Steven Goldfeder said the network's native bridge "has not been hacked or exploited in any way," and that the transaction came from a third-party protocol. A breach of Arbitrum's own bridge would ripple across the entire layer-2; a compromised app sitting on top of it is a contained failure.
AFX suspended bridge operations and said the damage looked "isolated to the AFX-operated custody bridge," noting that neither its trading infrastructure and mainnet, nor the Arbitrum network itself, had been compromised.
The firm added that it was working with ecosystem partners and security firms to trace the stolen assets. Hours later, AFX's head of growth, Ken C, offered the attacker a way out: return 70% of the haul and keep the other 30% as a "white hat bounty." Such public pleas have become a recurring feature of crypto exploits—Solana's Drift Protocol tried the same after its $285 million hack in April.
The theft extends a brutal year for DeFi, which has lost more than $840 million to hacks in 2026. It lands close to home, too, with fellow Arbitrum perpetuals venue Ostium drained of $18 million through a compromised oracle key just a week earlier.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。