AFX bridge on Arbitrum exploited for $24.15M USDC via compromised validator keys.
Security & Exploits ·
The AFX bridge on Arbitrum has been exploited for 24.15 million USDC, with the attacker moving the funds to Ethereum. The breach appears to have involved a validator key or backend compromise, as the transaction on Arbitrum shows the withdrawal was signed by five validators from a seven-validator set, exceeding the apparent threshold needed to authorize the transfer.
The attack surfaces questions about the security of the bridge's validator infrastructure. Seven distinct validator addresses are associated with the system, yet only five signatures were required to finalize the large withdrawal. This configuration suggests either a deliberate multi-signature threshold or a fault in how validator approval was managed at the time of the exploit.
The stolen USDC has been moved to an Ethereum address, where it now sits on-chain. It remains unclear whether the breach stemmed from private key compromise, a software vulnerability in the signing mechanism, or insider involvement. The AFX team has not yet disclosed details about their investigation or remediation steps.