Blockaid said on July 22, 2026, that an exploit drained approximately $24.15 million in USDC from a bridge operated by AFX Trade, a DeFi protocol on Arbitrum. Arbitrum’s own native bridge was not hacked or exploited, according to Offchain Labs CEO Steven Goldfeder.
Key Takeaways
- The exploit was detected at 21:30 UTC on July 22, draining about $24.15 million in USDC from a bridge AFX Trade operates, per Blockaid’s assessment.
- Offchain Labs CEO Steven Goldfeder confirmed the transaction originated from a third-party protocol and that Arbitrum’s native bridge was not hacked or exploited.
- On-chain security firm PeckShield traced the stolen funds moving from Arbitrum to Ethereum, where the attacker bought 12,467 ETH.
- Blockaid said its team is working with the Arbitrum team to help AFX Trade contain the stolen funds before more of the haul moves beyond Circle’s reach.
- AFX Trade is a DeFi protocol built on Arbitrum, the Ethereum layer-2 network developed by Offchain Labs.
What Happened?
Blockaid, the security firm that first flagged the incident, said its team has been working with the Arbitrum team to respond to the incident, engage with AFX Trade, and help contain the stolen funds. The firm published the exploit transaction from Arbitrum’s public ledger alongside its alert, pointing to a single transfer that moved the funds out of AFX Trade’s bridge contract.
Losses of this size land hard on a protocol’s own users and treasury first, well before they touch the wider market. PeckShield, an on-chain security firm, said the attacker moved the stolen USDC from Arbitrum to Ethereum and converted it into 12,467 ETH. Swapping a freezable stablecoin for ETH is a common laundering exit: USDC can be frozen, ETH cannot.
Blockaid detected an exploit at 2026-07-22 21:30 UTC targeting @AFX_XYZ, a protocol on @arbitrum. The exploit was specific to a bridge that AFX operates. Approximately 24.15M USDC has been drained thus far from the protocol.
— Blockaid (@blockaid_) July 22, 2026
Our team has been working with the incredible folks on… https://t.co/0Qd9ve5gPB
AFX Trade’s Bridge, Not Arbitrum’s
Early chatter framed the incident as an Arbitrum bridge hack. Offchain Labs pushed back within hours.
We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way.
— Steven Goldfeder (@sgoldfed) July 22, 2026
We will coordinate with the third…
Blockaid said the vulnerability was limited to the bridge that AFX Trade directly operates, not the canonical bridge contracts Arbitrum itself runs to move assets between Ethereum and the layer-2 network. A protocol built on a layer 2 network inherits none of that network’s own bridge security once it runs a custom bridge.
Implications for DeFi Bridge Security
A chain’s security budget does not automatically extend to every application built on top of it. That gap is where fraud data on DeFi incidents keeps repeating: custom bridge code, not base layer infrastructure, is where most protocol-level losses originate.
The stablecoin to ETH conversion follows a pattern security researchers see often: stolen funds move into a harder to freeze asset before an issuer can act. The practical question for AFX Trade’s depositors is whether the converted ETH can be traced and recovered, or whether the loss is a straight write-off. Funds parked in a third-party bridge carry a different risk profile than funds routed through a network’s own canonical bridge.
CoinLaw’s Takeaway
This incident reads as two separate stories wearing one headline: a $24.15 million exploit hit one protocol’s custom bridge. The base layer it runs on did not.
That distinction is easy to lose in fast-moving crypto coverage, where a network’s name becomes shorthand for anything built on it, regardless of who wrote the code that broke. Blockaid’s coordination with the Arbitrum team on containment does not change who bears the loss: AFX Trade’s depositors, not Arbitrum’s broader user base.
The USDC-to-ETH conversion is worth reading correctly, too. It is not a bet on Ether’s price. It is standard laundering mechanics: a freezable asset gets swapped for one that is not, before Circle or law enforcement can intervene.
Bridge exploits on general-purpose layer-2 networks tend to follow this same script. The AFX Trade case adds one more data point to a pattern that has repeated across DeFi for years: audited code and a reputable base chain do not, on their own, guarantee a safe bridge.