In a recent setback for DeFi ecosystem participants active on Arbitrum, the perpetuals trading platform AFX Trade experienced a substantial security breach targeting one of its proprietary bridges. Blockchain security firm Blockaid first identified the incident around 21:30 UTC on July 22, 2026, reporting that attackers had extracted approximately $24.15 million in USDC from the affected contract.
AFX Trade operates as a USDC-settled derivatives exchange on the Arbitrum network, offering users leveraged trading opportunities across various assets.
Deposits and withdrawals typically route through its dedicated bridge infrastructure, which held roughly $24.2 million in USDC prior to the event—nearly its entire locked value according to DeFiLlama data.
The exploit effectively emptied most of these funds, highlighting vulnerabilities that can arise even in established Layer-2 environments.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.
Our team has been working with the incredible folks on… https://t.co/0Qd9ve5gPB
— Blockaid (@blockaid_) July 22, 2026
Importantly, the breach was confined to AFX Trade’s own bridge implementation and did not involve Arbitrum’s native bridge infrastructure.
Steven Goldfeder, co-founder of Offchain Labs (the team behind Arbitrum), quickly addressed community concerns.
He confirmed that the suspicious transaction originated from a third-party protocol and emphasized that Arbitrum’s core bridging system remained secure and uncompromised.
The Arbitrum team is actively investigating alongside affected parties.
Blockaid has been collaborating closely with Arbitrum developers and AFX Trade to manage the response, investigate the root cause, and explore options for containing or recovering the stolen assets.
On-chain observers, including PeckShield and Lookonchain, tracked the attacker’s subsequent moves: the drained USDC was rapidly bridged to Ethereum mainnet and converted into roughly 12,467 ETH at an average price near $1,937.
The funds now sit in an attacker-controlled address, a common tactic to obscure trails and hinder immediate recovery efforts.
This event underscores the persistent challenges bridges face in DeFi. These components often custody large asset pools while relying on intricate smart contract logic and cross-chain messaging, making them attractive targets.
AFX Trade’s bridge had seen growing deposits in recent weeks, rising from about $19.3 million in mid-June, which likely increased its visibility to potential adversaries.
The incident follows other recent security events on Arbitrum, such as the mid-July exploit affecting Ostium’s vault.
While no official statement from AFX Trade had appeared on its social channels shortly after the breach, users and the broader ecosystem await updates on compensation plans, enhanced security measures, or any forensic findings.
Market reactions remained relatively contained in the immediate aftermath, with minimal movement in ARB and ETH prices.
However, such exploits can erode confidence in protocol-specific infrastructure and prompt heightened scrutiny of bridge designs across Arbitrum-based projects.
Developers and users alike are reminded of the importance of rigorous audits, ongoing monitoring, and diversified risk management in decentralized trading environments.
As investigations continue, this case serves as yet another concerning reminder of the evolving threat landscape in Layer-2 DeFi. Protocols must prioritize robust, isolated security for auxiliary components like bridges to safeguard user funds and maintain ecosystem trust.