AFX Trade’s USDC custody bridge suffered a $24.15 million security breach on July 22, draining nearly all capital held in the Arbitrum-based contract. Blockaid detected the incident at approximately 21:30 UTC and identified the target as a bridge operated by AFX rather than Arbitrum’s native infrastructure.
AFX acknowledged an incident involving its USDC custody bridge through its official account. The distinction is critical because the breach affected infrastructure managed by the trading protocol, while Arbitrum’s base network and native bridge continued operating normally.
AFX is aware of an incident involving the AFX-operated USDC custody bridge on Arbitrum.
Upon detecting the incident, we immediately suspended bridge operations and initiated our incident response procedures. Our engineering and security teams are actively investigating the root…— AFX Trade (@AFX_XYZ) July 23, 2026
Bridge Authorization Layer Becomes the Failure Point
DefiLlama classifies the incident as an infrastructure exploit involving compromised private keys, rather than a direct failure of Arbitrum or its consensus system. Its security database records the July 22 loss at $24.15 million and identifies Arbitrum as the affected deployment environment.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.
Our team has been working with the incredible folks on… https://t.co/0Qd9ve5gPB
— Blockaid (@blockaid_) July 22, 2026
That classification suggests the attacker obtained enough signing authority to approve an unauthorized withdrawal. In this type of bridge architecture, smart contracts can execute exactly as programmed while still releasing assets if the credentials authorizing a transfer have fallen into the wrong hands.
The failure therefore sits within key custody, signer independence and administrative security. A threshold-signature design is intended to prevent unilateral withdrawals, but that protection weakens when multiple signing credentials are stored, operated or compromised through related infrastructure.
DefiLlama now shows AFX Bridge TVL below $50,000 and down approximately 99.8% over 30 days, confirming that the incident removed nearly the entire balance previously locked through the Arbitrum contract. Its methodology counts USDC deposited and held in the AFX bridge.
Recovery Depends on Reserve Reconciliation
AFX’s acknowledgement confirms the protocol is treating the event as a bridge-specific security incident, but a complete technical postmortem has not yet established how the signing credentials were compromised. The project also has not detailed a compensation framework or timetable for restoring bridge operations.
For affected users, the central issue is whether AFX retains sufficient reserves to honor outstanding bridge-linked claims. A protocol can continue running its trading infrastructure while still facing a separate solvency gap inside the custody mechanism connecting its settlement environments.
The exploit demonstrates how off-chain operational security can override otherwise functional on-chain controls. Multisignature contracts, waiting periods and quorum rules cannot protect reserves when attackers gain control of the credentials those safeguards are designed to trust.
AFX faces a major bridge-liquidity and confidence failure rather than an Arbitrum network compromise. The next critical disclosures will be the root cause of the key breach, signer-security changes, final reserve accounting, recovery efforts and any plan to compensate users whose capital was held through the affected bridge.
