Tuesday, August 11, 2026 Latest news About 📈 Live coin prices →
DeFi

A $24M Heist Just Hit an Arbitrum Trading App — Here’s What Went Wrong

AFX Trade lost $24M when its own USDC bridge was breached. Here's what that means for your funds on DeFi apps.

Daniel Okafor3 min read
A $24M Heist Just Hit an Arbitrum Trading App — Here’s What Went Wrong

If you’ve ever moved money into a DeFi trading app and assumed the “bridge” connecting it to other blockchains was just plumbing you didn’t need to think about, this week’s news is a reminder that those bridges can be exactly where things go wrong. AFX Trade, a decentralized perpetuals exchange built on Arbitrum, lost roughly $24.15 million on Wednesday after attackers broke into a USDC custody bridge the platform itself operates.

Security firm Blockaid flagged the incident, and AFX confirmed it was aware of a breach tied to that bridge. Crucially, the exploit didn’t touch the Arbitrum network itself — this was a problem with AFX’s own infrastructure for moving stablecoins in and out of its platform, not a flaw in the underlying blockchain.

Where the money went

On-chain sleuths moved fast. Blockchain analytics firm PeckShield tracked the stolen USDC as it was bridged over to Ethereum and swapped into 12,468 ETH, all of which is now sitting in a single wallet. That kind of quick, visible trail is common in crypto hacks — the funds aren’t hidden, they’re just out of reach unless the attacker decides to give them back or tries to cash out through an exchange that can freeze the assets.

AFX has already shut down the affected bridge to stop any further losses while it investigates exactly how the attacker got in. The team says the precise attack vector is still unknown, which is a fairly normal first response to a fast-moving exploit — freeze what you can, then figure out the “how” afterward.

A public offer to the hacker

In a move that’s become something of a playbook in DeFi hacks, AFX publicly offered the attacker a deal: return 70% of the stolen funds and keep the remaining 30% as a so-called “white hat bounty.” It’s an unusual kind of negotiation, essentially treating the thief as an accidental bug bounty hunter rather than pursuing a purely legal route.

This tactic has worked before in the crypto world — some hackers have taken similar deals rather than risk being tracked down or having stolen funds frozen at exchanges. Whether AFX’s attacker takes the offer remains to be seen, and there’s no guarantee here; it’s simply the fastest lever protocols have when a full recovery through hacking back isn’t realistic.

What this means if you use DeFi apps

For everyday crypto holders, the key takeaway isn’t about Arbitrum being unsafe — the network itself wasn’t compromised. It’s about understanding that many DeFi platforms run their own custom infrastructure, like custody bridges, to move your funds between chains, and that infrastructure carries its own separate risks on top of the blockchain it sits on.

Before parking funds in any perpetuals exchange or DeFi app, it’s worth checking whether the platform relies on a proprietary bridge or custody system, since these have repeatedly been targets for attackers across the industry. Bridges moving stablecoins between chains have been a recurring soft spot in crypto security, and this incident adds another entry to that list.

Read more: A Cardano Bridge Just Got Drained — So Why Did ADA Rally Anyway?

Sources

More DeFi