AFX Trade, a decentralized perpetuals exchange on Arbitrum that settles trades in USDC, lost about $24.15 million after an attacker used compromised validator signing keys tied to a bridge used by the protocol. The breach appears to have drained nearly all of the platform’s total value locked.
Bridge approvals enabled the withdrawal
According to the report, the attacker obtained enough validator signatures to satisfy the bridge’s withdrawal requirements. Security firm Blockaid said the smart contract logic itself behaved as intended: five hot-validator signatures were sufficient to reach quorum and authorize the transfer.
That means the exploit was not described as a failure of the bridge’s on-chain code. Instead, the weakness was in control of the signing keys. Once the required approvals were presented, the contract treated the request as legitimate and released the funds after a 200-second dispute window.
Arbitrum bridge not affected
The incident involved a bridge used by AFX on Arbitrum, not Arbitrum’s native bridge. The source article states that Arbitrum’s own bridge infrastructure was not breached.
This distinction is central to how the theft unfolded. The bridge mechanism processed the withdrawal under its existing rules, but the validator credentials authorizing the transaction were apparently in the attacker’s possession. In other words, the system executed a valid-looking request with compromised approvals rather than being broken through a flaw in the execution logic.
Funds moved to Ethereum and swapped for ETH
After the withdrawal was approved, the attacker moved the stolen USDC to Ethereum. The funds were then swapped for about 12,467 ETH, valued at roughly $24 million at the time cited in the report.
The article says the ETH now sits in a single wallet. The sequence of transfers effectively converted the stolen stablecoins into ether shortly after the assets left AFX-linked infrastructure.
Attack struck as activity was rising
The loss came during a period of stronger usage for AFX Trade. In the run-up to the incident, the protocol’s daily perpetuals trading volume had climbed to multi-month highs in mid-July, according to the source. That rise in activity also coincided with increased user deposits.
As a result, the attacker appears to have hit the protocol when funds held by it were near a local peak. The roughly $24 million removed was described as nearly the entirety of AFX’s total value locked, leaving the platform’s vault effectively emptied.
The incident was reported as part of a broader stretch of crypto security breaches, including hacks affecting Arbitrum-based protocols. In this case, the reported facts point to compromised validator keys, not a failure of Arbitrum’s native bridge or of the bridge contract’s intended on-chain behavior.
Source: www.coindesk.com