AFX Trade Loses $24 Million After Bridge Validator Keys Are Compromised

The smart contracts held up fine. It was the seven people holding the keys to a side door that gave an attacker everything they needed.
AFX Trade, a decentralized perpetuals exchange built on Arbitrum, was drained of $24.15 million on July 22 after an attacker compromised the validator signing keys controlling the protocol’s bridge — reportedly gaining access to five of the bridge’s seven validator keys, enough to move funds out without further restriction. The stolen USDC was bridged to Ethereum and converted into ETH.
Security firm Blockaid flagged the incident as part of a wider cluster of attacks it labeled Hackers Day, with cumulative crypto losses from hacks during July 2026 reaching close to $97 million across multiple separate incidents.
What makes the AFX Trade case a useful study is where the weak point was. The exploited bridge was maintained directly by the AFX Trade team, rather than being a feature of Arbitrum itself — meaning the vulnerability sat in project-specific, off-chain infrastructure rather than any flaw in the actual trading smart contracts.
In the aftermath, AFX Trade publicly offered the attacker a 30% bounty to return the remaining funds, framing partial recovery as a better outcome than an adversarial standoff. This has become close to standard practice after major exploits.
The broader pattern researchers point to in 2026’s hacking activity: attackers are increasingly targeting off-chain infrastructure — bridge validator keys, multisig signers, and operational security — rather than hunting for smart contract bugs directly, since well-audited contracts have made that older attack path comparatively harder.
Want to understand how cross-chain bridges work and why they’re a common attack target? Learn more in the Bitcoin Academy.
