Arbitrum bridge exploit drains $24m from AFX Trade
Arbitrum bridge exploit drained about $24.15 million from AFX Trade, reviving scrutiny of bridge custody, collateral access and liquidity risk.

AFX Trade was hit by a $24.15 million bridge exploit on Arbitrum late Wednesday, security firms said, after an attacker moved stolen USDC to Ethereum and swapped it into 12,467 ETH. The Block first reported the breach. The Defiant said on-chain investigators traced the funds after they left Arbitrum, and PeckShield also flagged the transfer route.
The damage appears to have sat inside an AFX-operated bridge, not Arbitrum’s native infrastructure. For decentralised finance users, that is the important line. Bridges are the points where assets move between chains; traders use them to shift stablecoins, collateral and liquidity between venues.
A failure there can become a market-access problem quickly.
Blockaid said “the exploit was specific to a bridge that AFX operates,” pointing to protocol-controlled code rather than the wider network. The timing was tight. Blockaid detected the exploit at 21:30 UTC, The Defiant reported, and the AFX bridge held about $24.2 million just before the attack, citing DefiLlama. If those figures are confirmed, nearly the whole balance in that channel was swept out in one move.
According to The Defiant’s report, the attacker bridged the stolen USDC from Arbitrum to Ethereum before converting it into ether. That choice changes the clean-up problem. A move from a dollar-pegged token into ETH can complicate exposure monitoring for platforms and users, even when the wallets remain visible on-chain.
For Arbitrum users, the difference between an application bridge and the chain’s native bridge is more than a technical footnote. The failed component sits at the seam between custody, settlement and liquidity. One broken bridge can reach derivatives positions, collateral management and redemption flows even while the base chain keeps producing blocks normally. The direct loss is $24.15 million. The secondary risk is discovering that assets treated as portable were concentrated behind one operational choke point.
Steven Goldfeder, co-founder of Offchain Labs, which developed Arbitrum, tried to draw that boundary in public. In comments cited by The Defiant, Goldfeder said “the Arbitrum native bridge has not been hacked or exploited in any way.”
Why the distinction matters
Goldfeder’s comment narrows the risk map for users. The public record points to AFX’s bridge design or controls, not the core Arbitrum bridge used by many applications. That does not make the loss small. It changes the question from whether Arbitrum itself was compromised to whether individual protocols have enough safeguards around the bridges they operate.
AFX sits in derivatives, where confidence in collateral movement can be as important as price direction. If traders cannot rely on a bridge to move USDC in and out of a venue, the failure starts to resemble a custody break in traditional markets. Positions may stay open. Hedges become harder to fund. Users have to decide which intermediaries they still trust for settlement.
What remains public is narrow but consequential: roughly $24.15 million was drained, the funds were traced into 12,467 ETH, and security researchers say the exploit was ring-fenced to an AFX-operated bridge rather than Arbitrum’s native one. Until AFX or independent auditors publish a fuller post-mortem, users are left with a practical question: how much bridge risk sits inside each cross-chain transfer?
Caleb Mwangi
Crypto correspondent covering bitcoin, ether, altcoins and on-chain markets. Reports from Singapore.


