A week after the Ostium oracle used Arbitrum, another always DEX on the same network was shed. On July 22, 2026, AFX Trade lost approximately $24.15 million USDC after an attacker compromised the signing keys behind the bridge where the protocol operates. The stolen money was transferred to Ethereum and exchanged for about 12,467 ETH – almost bringing out the entire value of the closed platform.
Again, the weak point was not a smart code. It was the chain link that sat around, and in this case the bridge that AFX drove itself and not Arbitrum’s.
What happened to AFX Trade?
Security company Blockaid announced at 21:30 UTC on July 22. The attacker gained access to the valid signing keys of the AFX bridge for USDC – the part that allows people to log out. With enough signals to complete the bridge count, negative removal was considered acceptable to the system.
The following information is required: Blockaid saw that the on-chain concept worked as intended. Five official signatures met the threshold required to approve the transfer, so the union released the money without any errors. The problem was that the signature keys were in the wrong hands.
After clearing the room, the attacker cut USDC from Arbitrum to Ethereum and exchanged about 12,467 ETH for an average of $1,937 per token. According to PeckShield, the converted ETH was merged into a single wallet.
Has the Arbitrum network been hacked?
No – and that distinction is important. The exploit hit a third-party bridge that AFX maintains on top of Arbitrum, not Arbitrum’s own bridge or Layer 2. Steven Goldfeder, co-founder of Offchain Labs (the group behind Arbitrum), said the normal network bridge was not hacked or exploited in any way.
A breach of the Arbitrum bridge would disrupt the entire Layer 2 environment. The tampering program sitting on top of it, in contrast, is a failure – bad for AFX and its users, but not a systemic threat to other Arbitrum protocols.
Why are bridges such a common target?
Bridges has become one of the most destructive forms of destruction DeFi for years, and because it is structural. They have large pools of locked resources and rely on standard sets or multisig settings to allow transfers. This checks for the trust of a small key – and if that key is tampered with, the code on the chain will happily accept a discount that appears to be properly signed.
The AFX event fits the pattern exactly. The trading engine and architecture of Arbitrum are not affected; The only weak link was the signing of the bridge that the team operated itself. It parallels the larger story of 2026, in which most of DeFi’s losses stemmed from faulty assets rather than faulty Stability.
Looking for a more streamlined option? Browse our list of MiCA-approved exchanges
How much has been stolen, and where is the money?
About $24.15 million in USDC was downloaded – close to the total TVL of the protocol. Unlike many cases where money goes missing in the mixer, here the method is still clear: the attacker exchanged USDC for about 12,467 ETH and left it sitting in a known Ethereum wallet, with no significant withdrawal reported. Security companies Blockaid and PeckShield are actively tracking the address.
That the money is not removed but leaves a narrow window for recovery – which is exactly what AFX is trying to take advantage of.
What is AFX doing to get the money back?
A few hours after the attack, AFX stopped the damaged bridge and made a public offer to the attacker: return 70% of the stolen goods and keep the remaining 30% – about $ 7.2 million – as a “white hat.” The group posted a real Ethereum address to return.
This has become the playbook in crypto transactions. The idea is clear: the recovery of 70% of attacks has not found anything, and modern legal experts make it more difficult to hack without detection. It’s not without its critics, however — some security researchers argue that payers manage a “steal first, negotiate later” dynamic. Whether it works here depends entirely on whether the attacker likes to whitewash the risk of trying to move ETH.
To date, the exact way the keys were compromised is still being investigated, and the money remains in the attacker’s wallet.
What does the AFX hack mean for DeFi traders?
For anyone who uses permanent DEXs on a Layer 2 network, the lesson is to look below the transaction interface. A protocol can have hard contracts for its perps engine and be fired if the bridge it relies on has a central authentication key. The events of AFX and Ostium within a week – both on Arbitrum, both unrelated – make this point hard to ignore.
Useful for traders: understand if the platform is dependent on a self-driving bridge, be careful with the money you leave parked in one place, and follow the official procedures instead of just talking about the rumors.
Where can you trade crypto on regulated platforms instead?
Incidents like the AFX hack are a reminder of the trade-offs that come with unaccounted-for or unmanaged assets. In the EU, the MiCA system now implements a similar policy: from July 1, 2026, every platform for sending EU clients requires a Crypto-Asset Service Provider (CASP) license, covering governance, client security, IT security, and AML requirements. By the end of July 2026, ESMA’s register listed around 300 authorized CASPs across the EEA, with one authorization per member state.
If you would like to trade on an official, legal platform instead of showing money to a bridge or oracle-dependent perp DEX, it is better to compare the licensed sites, fees, and assets available. Our broker and exchange comparison page breaks these down side by side so you can choose the platform that best suits your trading style.
One method is controlled by XTB imagesa publicly listed broker, who has obtained a license to offer crypto trading to EEA clients (through a Cyprus license), along with its authorized trading. You can open an account with XTB on.






