AFX suffered a $24.15 million USDC loss after an attacker focused a cross-chain bridge linked to the buying and selling protocol on July 22.
Abstract
- AFX’s cross-chain bridge misplaced $24.15 million USDC whereas Arbitrum’s native bridge remained unaffected throughout assault.
- The exploiter moved stolen USDC to Ethereum and transformed the proceeds into 12,467.5 ETH afterward.
- Safety corporations are tracing the stolen funds as AFX and Arbitrum groups examine the breach.
The incident triggered an investigation by Blockaid and the Arbitrum workforce, whereas on-chain trackers adopted the stolen funds to Ethereum.
The assault didn’t have an effect on Arbitrum’s native bridge. AFX operates its personal sovereign Layer 1 for perpetual buying and selling however accepts USDC deposits by way of Arbitrum. The affected infrastructure was a third-party bridge operated by AFX relatively than Arbitrum’s core bridge.
AFX bridge loses $24.15 million USDC
Blockaid mentioned it detected the exploit at 9:30 p.m. UTC on July 22. The agency mentioned the assault focused a bridge operated by AFX and drained about 24.15 million USDC. An Arbiscan report reveals a profitable switch of 24,150,000 USDC from the bridge contract to the recipient handle at 9:30:25 p.m. UTC.
The safety agency mentioned it was working with the Arbitrum workforce to reply, contact the affected protocol and assist include the stolen funds. Based mostly on the general public updates reviewed at publication time, no restoration had been confirmed.
AFX had additionally not revealed a verified technical postmortem explaining how the attacker gained authorization to withdraw the funds. The protocol had not introduced a restoration plan.
Offchain Labs co-founder Steven Goldfeder confirmed that the suspicious transaction got here from a third-party protocol. He additionally separated the AFX incident from Arbitrum’s personal bridge infrastructure.
“We’re conscious of a report of a bridge hack on Arbitrum and are investigating. We will verify that the transaction in query originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any approach,” Goldfeder mentioned.
He added that the workforce would coordinate with the third-party protocol and share extra particulars when obtainable.
AFX makes use of Arbitrum as a route for USDC deposits whereas operating its buying and selling system on a devoted Layer 1. AFX describes itself as a decentralized derivatives platform constructed round a sovereign execution setting. A current protocol submit additionally mentioned customers may deposit USDC from Arbitrum earlier than accessing its perpetual markets.
Exploiter converts stolen USDC into ETH
PeckShield mentioned the attacker moved the stolen USDC from Arbitrum to Ethereum and transformed the proceeds into 12,467.5 ETH. Lookonchain individually reported that the exploiter purchased about 12,467 ETH at a median value close to $1,937 per ETH after shifting the funds.
The conversion moved the stolen worth from a U.S. dollar-pegged stablecoin into Ether, exposing the holdings to ETH value actions. Safety groups continued tracing the funds after the swap. At publication time, the reviewed sources didn’t verify that Circle had frozen the USDC earlier than conversion or that any of the ETH had been recovered.
The assault provides to a number of bridge-related safety incidents this yr. As crypto.information beforehand reported, Stake DAO closed its vsdCRV bridge after an unauthorized mint on Arbitrum in Might. The undertaking mentioned it secured the token’s mainnet backing and contained the incident to the affected bridge.
Earlier in April, a bigger exploit hit Kelp DAO’s LayerZero-powered bridge. Attackers drained roughly 116,500 rsETH price about $292 million. Arbitrum later froze greater than 30,000 ETH linked to that attacker after the funds moved onto Arbitrum One.
Investigation focuses on AFX-operated infrastructure
The investigation now facilities on the AFX-operated bridge and the authorization course of behind the 24.15 million USDC withdrawal. The confirmed transaction reveals that the bridge contract finalized the switch, however public statements don’t but set up the verified root trigger. A full postmortem could decide whether or not the incident concerned compromised validator credentials, defective entry controls or one other weak point.
The principle confirmed level is that the exploit affected infrastructure operated by AFX relatively than Arbitrum’s native bridge. Blockaid and Offchain Labs each made that separation clear of their preliminary responses. The Arbitrum community continued working, and reviewed stories confirmed no loss from its native bridge.
The incident additionally locations consideration on AFX’s deposit infrastructure. The protocol has promoted USDC deposits from Arbitrum as an entry route into its buying and selling platform. Any modifications to deposits, withdrawals or bridge operations will rely on the protocol’s response and the continued investigation.
The case stays creating. The confirmed loss stands at about $24.15 million in USDC, whereas on-chain trackers have traced the stolen worth into roughly 12,467 ETH on Ethereum. Additional updates are anticipated from AFX, Blockaid and the Arbitrum workforce as they evaluate the breach and monitor the attacker’s funds.


