AFX Trade Offers $7.2M Whitehat Bounty to Recover 70% of $24.15M USDC Stolen in Bridge Attack
AI Market Summary
AFX Trade's $24.15M USDC bridge loss on Arbitrum highlights persistent bridge and key-management risk, with the attacker swapping proceeds into ETH. While Arbitrum's native bridge was unaffected, the incident reinforces that offchain validator signing keys can be a critical failure point beyond smart-contract audits. The public 30% whitehat-style bounty offer underscores recovery uncertainty and can weigh on risk appetite across Arbitrum DeFi.
Impact level
● Medium
Affected assets
AR/USDT-2.95%
AI Insight · AR/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
AFX Trade, an Arbitrum-based decentralized exchange, is seeking to claw back funds after losing $24.15 million in USDC in a bridge exploit. The protocol has publicly proposed a "whitehat" bounty that would allow the attacker to keep 30% of the proceeds—about $7.2 million—in return for sending back the remaining 70%.
The offer was outlined by AFX head of growth Ken C, effectively opening negotiations with the party behind the theft.
The breach occurred on July 22, 2026 and targeted AFX Trade's custody bridge, not its smart contracts or Arbitrum's core infrastructure. Investigators said the attacker obtained offchain validator signing keys and used them to drain roughly $24.15 million in USDC from the bridge.
After the theft, the funds were moved to Ethereum and swapped for about 12,467 ETH, with ETH trading near $1,937 at the time. AFX said it suspended the bridge shortly after detecting the incident.
Security firms Blockaid and PeckShield confirmed the exploit and emphasized that Arbitrum's native bridge was not impacted.
The AFX incident came during a cluster of attacks on July 22 and 23 that pushed combined losses above $35 million across multiple platforms. Looking at the broader month, Blockaid and PeckShield data show total hack-related losses in July 2026 nearing $97 million.
The episode underscores a recurring risk in bridge security: the failure point was not a smart-contract bug. The contracts behaved as intended, but offchain validator key management proved vulnerable—an area often less visible to users than audits, despite representing a sizable attack surface.