AFX Bridge on Arbitrum Drained of $24M in USDC in Targeted Exploit
An attacker drained ~$24M in USDC from AFX's Arbitrum bridge in a targeted exploit. Arbitrum's native bridge was confirmed unaffected. USDC holds its peg.
An attacker drained approximately $24 million in UUSDC$0.9998▲0.00% from a bridge operated by derivatives exchange AFX on Arbitrum, emptying nearly all of the stablecoin locked in the contract. Security firm Blockaid identified and reported the exploit, which targeted AFX’s bridge infrastructure rather than the network’s core exchange or native cross-chain bridge.
According to The Defiant, the drain represented close to the entirety of USDC held in the bridge contract — a near-total wipeout, not a partial extraction. Arbitrum co-founder Steven Goldfeder publicly confirmed the network’s native bridge was not affected, a statement clearly aimed at containing the contagion fears that tend to cascade after any high-profile bridge incident. The distinction matters: Arbitrum’s official bridge, which secures far larger sums, remained intact.
AFX is a derivatives exchange. The exploited contract was a bridge it operated on the Arbitrum network, separate from its core trading infrastructure. No exploit vector, attacker wallet address, or transaction hash has surfaced in available reporting. Blockaid has not published a technical breakdown, and AFX has not issued a post-mortem or outlined any compensation plan.
A Reddit thread titled “AFX Trade Exploited for $24 Million in Bridge Attack on Arbitrum” is circulating in r/CryptoCurrency. Users there are discussing the incident, but the thread introduces no new on-chain evidence beyond what The Defiant reported — treat it as unverified community noise.
USDC itself is unmoved. The stablecoin is trading at $0.9998, holding its dollar peg, with a market capitalization of $73.18 billion and 24-hour volume of $10.04 billion. The $24 million pulled from AFX’s bridge is a real loss for affected users but a rounding error against USDC’s total circulating supply. No bank-run dynamic, no de-peg event.
A Cluster of Arbitrum Attacks
This is the latest in a cluster of attacks hitting Arbitrum-based protocols. The Ostium hacker recently laundered 10,540 EETH$1,921.76▼0.70% through Tornado Cash following a separate $24 million Arbitrum vault exploit — a distinct incident, not to be conflated with the AFX drain. Allbridge Core was also halted after a $1.65 million flash loan exploit drained a stablecoin pool. Arbitrum’s growing DeFi ecosystem is pulling in legitimate volume and adversarial attention in roughly equal measure, and bridges keep absorbing the hits.
Market Backdrop
The broader market was already skittish before this landed. Total market capitalization sits at $2.32 trillion, down 0.87% over 24 hours. The Fear & Greed Index reads 31 — squarely in “Fear” territory. BBTC$65,662.00▼1.00% is at $65,592, off 1% on the day; Ethereum sits at $1,920, down 0.6%. A nine-figure bridge exploit into an already stressed market compounds the negative sentiment, though the confined scope of this attack limits any real systemic spillover.
What Remains Unknown
What nobody knows yet is how the attacker got in — reentrancy bug, access control flaw, oracle manipulation, or something else entirely. No attacker wallet has been flagged on-chain in available reporting. Blockaid’s alert identified the drain but stopped short of specifying a root cause. AFX’s official channels have gone quiet. The next concrete signal is whether AFX or Blockaid releases a technical post-mortem with a transaction hash and attacker address — until then, the exploit’s mechanics and any realistic path to fund recovery remain open questions.