AFX Trade, a trading protocol built on the Arbitrum network, was drained of roughly $24 million after attackers compromised the private keys controlling its cross-chain bridge, security researchers confirmed this week.
How the Attack Unfolded
According to blockchain security firms tracking the incident, the attacker gained access to enough hot-validator signatures to authorize a fraudulent withdrawal totaling 24.15 million USDC. Because the bridge relied on a small set of signing keys held in an online environment, the intruder was able to meet the signature threshold required to approve the transfer without triggering safeguards.
The exploit did not involve a flaw in the underlying smart contract logic, but rather the security of the credentials that governed access to the bridge. Once the attacker controlled the necessary keys, the withdrawal was pushed through and the stablecoins were moved out of the protocol's control.
When the keys guarding a bridge fall into the wrong hands, the code protecting user funds becomes almost irrelevant.
Arbitrum Distances Itself
Arbitrum was quick to clarify that its native bridge was not affected by the breach. The incident was isolated to AFX Trade's own bridging infrastructure, which operated independently of the layer-2 network's core bridging mechanism.
The distinction matters for users and investors trying to gauge the scope of the damage. Native Arbitrum bridge assets and the broader ecosystem remained secure, with the losses confined to the compromised third-party protocol.
Bridge exploits have long ranked among the most costly categories of attacks in crypto, with hundreds of millions lost across various protocols in recent years. Hot-wallet and validator-key compromises are a recurring theme in these breaches.
- The stolen amount totaled 24.15 million USDC.
- The breach stemmed from compromised hot-validator signatures.
- Arbitrum's native bridge was confirmed unaffected.
Investigators are continuing to trace the movement of the stolen funds, while questions remain about how the signing keys were exposed and whether affected users will be made whole.
