AFX Trade has paused its Arbitrum-operated USDC custody bridge after approximately $24.15 million in USDC was drained on July 22, 2026, according to a Blockaid alert. The incident was detected at 21:30 UTC, targeting AFX’s bridge infrastructure rather than Arbitrum’s native bridge. The exact root cause remains under investigation by the project, while security firms monitor the flow of stolen funds to support recovery efforts.
AFX Pauses Bridge After $24.15M USDC Drain
AFX confirmed an incident involving its AFX-operated USDC custody bridge on Arbitrum, which handles USDC deposits/withdrawals for the project’s trading ecosystem. Immediately upon detecting the incident, AFX stated it paused bridge operations and activated its incident response procedures.
AFX is aware of an incident involving the AFX-operated USDC custody bridge on Arbitrum.
Upon detecting the incident, we immediately suspended bridge operations and initiated our incident response procedures. Our engineering and security teams are actively investigating the root…— AFX Trade (@AFX_XYZ) July 23, 2026
Initial assessments indicate the incident appears isolated to the project-operated custody bridge. AFX stated that its trading infrastructure, AFX mainnet, and the Arbitrum network were not compromised.
Offchain Labs shared a similar message. Steven Goldfeder, co-founder and CEO of Offchain Labs, stated that the relevant transaction originated from a third-party protocol, while Arbitrum’s native bridge was neither hacked nor exploited. This information further indicates that the damage was concentrated on AFX’s bridge, though the scale of the loss for the project remains substantial.
Funds Flow to Ethereum
Blockaid reported that the exploit was detected at 21:30 UTC on July 22, 2026, with approximately $24.15 million in USDC drained from the AFX-operated bridge. This figure almost matches AFX Bridge’s pre-incident TVL. DefiLlama data logged AFX Bridge with around $24.18 million in TVL, all situated on Arbitrum, representing nearly the entirety of the locked assets in the bridge.
After draining the USDC, the attacker transferred the assets from Arbitrum to Ethereum. PeckShield tracked the funds flow, noting that the stolen USDC was subsequently swapped into approximately 12,467.5 ETH. This ETH was traced back to wallet 0x6276…ebAC.

Attacker wallet holding swapped ETH. Source: PeckShield
USDC is a stablecoin issued by Circle and can be frozen at the token contract level under certain circumstances. ETH lacks a similar mechanism, so once assets are swapped and consolidated into an Ethereum wallet, recovery relies more heavily on on-chain monitoring and exchange coordination.
AFX Works to Recover Funds
AFX stated it is working with blockchain security partners as the investigation continues. Meanwhile, SlowMist noted that the stolen funds remain in the attacker’s address, which has been reported to the Crypto Defense Alliance (CDA)—a collaborative network of exchanges and ecosystem partners. AFX said the associated address is being monitored by ecosystem stakeholders.
The project also mentioned that Zellic, the firm that previously audited the bridge code, has been invited to assist in the investigation. A technical postmortem from AFX and security firms will serve as the basis to determine whether the incident involved code vulnerabilities, validator setup, key management, or backend signing flows.
In parallel with the investigation, AFX amplified a white-hat settlement offer from Ken / Supercube, Head of Growth at AFX. The offer requests the party responsible for the bridge incident to return 70% of the stolen assets to address 0x222B…9f1B, while retaining the remaining 30% as a white-hat bounty.
We are extending a white hat settlement offer to the party responsible for the recent bridge incident.
Return 70% of the stolen assets to the following address:
0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1BYou may retain the remaining 30% as a white hat bounty.
Our priority is…
— Ken / Supercube🧊 (@supercubeguy) July 23, 2026
AFX’s recovery messaging currently focuses on two objectives: protecting the community and maximizing the potential recovery of user assets. However, at the time of writing, there is no public confirmation that any portion of the stolen funds has been returned.
Root Cause Still Under Investigation
AFX has not yet announced the final attack vector. In official updates, the project only stated that the investigation is ongoing and that further information will be provided as verified data becomes available. Therefore, there is currently no basis for a definitive conclusion on whether this was a smart contract exploit or a validator key compromise, beyond assessments from security sources.
Nevertheless, several security sources and DeFi data aggregators have categorized the event as an infrastructure incident. SlowMist described it as an exploit targeting AFX’s cross-chain/USDC custody bridge on Arbitrum, suggesting the attacker used compromised validator hot keys to achieve a payout quorum. The DefiLlama Hacks database also recorded a $24.15 million loss for AFX Bridge, classifying it as “Infrastructure” with the technique labeled “Private Key Compromised.”
If the postmortem confirms this classification, the AFX incident will serve as another example of operational risks at the bridge layer, including signing keys, validator setups, custody processes, and withdrawal verification mechanisms. Bridges typically hold large asset volumes in contracts or custody layers, making procedural flaws in verification capable of causing concentrated losses.
AFX has not disclosed the number of affected keys or validators, the specific role of the bridge code, or user reimbursement plans. The project has also not confirmed any recovery from the stolen funds. The final technical root cause remains pending verification from AFX and investigative teams.