AFX Trade bridge drained of $24.15M after attackers compromised hot-validator signatures and approved unauthorized USDC withdrawal.
Security & Exploits ·
AFX Trade, a decentralized perpetuals exchange on Arbitrum, lost approximately $24.15 million in USDC after attackers compromised validator signing keys controlling the protocol's bridge. Security firm Blockaid confirmed that five hot-validator signatures—meeting the bridge's two-thirds quorum requirement—authorized the unauthorized withdrawal. The attacker subsequently moved the stolen USDC to Ethereum and converted it to approximately 12,467 ETH.
The compromise targeted the bridge's private validator keys rather than the underlying smart contract logic, which functioned as designed during the transaction. Arbitrum clarified that its native bridge was not affected and that the incident involved a third-party protocol built on top of the network. This mirrors earlier high-profile incidents where off-chain key compromises proved more damaging than on-chain code vulnerabilities, underscoring a persistent security gap in bridge operations even as base-layer infrastructure improves.
The incident follows a series of exploits targeting Arbitrum-based protocols in recent weeks. Whether additional security measures or operational changes will be implemented by AFX Trade or the broader bridge operator ecosystem remains unclear.