Arbitrum-based decentralized perpetual exchange AFX Trade lost 24.15 million USDC on July 22, 2026, at 21:30 UTC. The attacker drained nearly all of the protocol’s total value locked (TVL) just as trading volume surged to multi-month highs.
Security firm Blockaid detected the exploit and noted a key detail: AFX Trade’s smart contracts operated exactly as designed. Rather than exploiting a vulnerability in the smart contract code, the attacker compromised validator signing keys (hot keys) stored off-chain.
According to tracking by on-chain analytics account @lookonchain on X, the attacker managed to gather five validator signatures. This was enough to satisfy the two-thirds quorum required by the bridge to approve a 24,150,000 USDC withdrawal. The stolen funds were then bridged to the Ethereum network and swapped for 12,467 ETH at an average price of $1,937. All of these assets are currently consolidated in a single wallet controlled by the perpetrator.
Arbitrum Network Not at Fault
Concerns briefly spread regarding the underlying security of the layer-2 network itself. However, Steven Goldfeder, co-founder of Offchain Labs and Arbitrum, was quick to clarify that Arbitrum’s native bridge was not breached at all. The incident was purely a security failure on the part of a third party building on their network.
A string of exploits across the Arbitrum ecosystem has recently unfolded in quick succession. Just a week earlier, Ostium, a real-world asset (RWA) platform also operating on Arbitrum, lost $18 million to an oracle exploit. The AFX Trade incident further lengthens the grim record of the second quarter of 2026, which now ranks among the worst periods for crypto security.
The New Off-Chain Blind Spot
The attack pattern on AFX Trade is reminiscent of the Drift Protocol hack last April, which resulted in losses of up to $285 million. In Drift’s case, the attacker also spent months gaining privileged access to operating systems rather than attempting to breach the protocol’s core codebase.
The wave of breaches this year signals a shift in hacker tactics. Most attacks now target off-chain components where keys and administrative access are held. Building decentralized systems with hack-proof code becomes futile if the keys to the vault can be seized through traditional web vulnerabilities.
Hackers have realized that the real weak link in crypto projects lies in their supporting infrastructure, not in the complexities of the blockchain technology itself.
Sourced from CoinDesk.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




