AFX Trade, a decentralized crypto and stock perpetuals exchange, suffered an attack on its Arbitrum bridge. This exploit resulted in the exchange losing approximately $24.15 million in USD Coin [USDC].
The attacker quickly transferred the stolen funds from Arbitrum [ARB] to Ethereum [ETH]. This moved the assets beyond the original network, making recovery more difficult. The attacker then exchanged the USDC for 12,467.44 ETH, worth about $24.16 million.


Converting the frozen USDC to ETH provided the hacker with a new type of asset that could be transferred from platform to platform. After consolidating all the assets into one Ethereum wallet, there were no subsequent large withdrawals from the attackers’ wallet.
Meanwhile, the attacker’s Ethereum wallet address is now publicly known. This enables investigators and blockchain analysts to track any potential movement or attempt to transfer these assets.
AFX isolates breach to custody bridge
AFX traced the source of the lost funds to an individual Ethereum account. This turned their focus to controlling the damage caused by the hack and identifying how it occurred.
Immediately after discovering the loss, AFX suspended all activities on the bridge and activated its incident response plan. The exchange, in collaboration with blockchain security partners, began monitoring for additional movement of the stolen tokens.
AFX also confirmed that the suspicious transactions came from a third-party protocol, reinforcing that Arbitrum’s core infrastructure remained unaffected.


Meanwhile, SlowMist reported that the stolen funds still sit in the attacker’s wallet. As a result, this will allow the Crypto Defense Alliance (CDA) and several exchanges to monitor future movements.
Zellic, which previously audited the bridge code, has joined the investigation to review the attack vector. AFX has also extended a white hat settlement offer while continuing to trace the assets and publish verified updates.
Bridge attacks expose recurring risks
The AFX exploit reflects a pattern that has repeatedly emerged across third-party bridge attacks.
Arbitrum’s original native bridge was secure, but it was compromised through outside bridge infrastructure. This trend highlights the vulnerability of third-party bridges, making them easier targets for the exploits.
Similar incidents, including Ostium and Allbridge Core, show that attackers continue targeting connected protocols, underscoring the need for stronger security across cross-chain infrastructure rather than the networks themselves.
Final Summary
- AFX lost $24.15 million after attackers exploited its third-party custody bridge and moved the stolen funds from Arbitrum to Ethereum.
- Recurring bridge attacks highlight the need for stronger third-party security as cross-chain infrastructure continues to expand.
