AFX Trade drained of $24M, offers hacker 30%
Arbitrum perp DEX AFX Trade lost $24M when its own USDC custody bridge was exploited, not the chain itself.

AFX Trade, a perpetuals exchange running on Arbitrum, lost roughly $24 million when an attacker drained the USDC custody bridge the protocol operates itself. The team confirmed the breach never touched Arbitrum's base layer, and the stolen funds moved to Ethereum within hours.
What the numbers say
The exploit hit a bridge AFX built and ran, not the underlying Arbitrum chain, which puts this in the same category as dozens of custody-layer failures that get mistaken for chain-level breaks. AFX has publicly offered the attacker a 30% cut, roughly $7.2 million, to return the rest, a standard whitehat bounty play seen after incidents at Euler, Poly Network and others. The company hasn't disclosed how the bridge was structured, what multisig or validator set controlled it, or whether the exploit involved a signature forgery, a logic bug, or a compromised key. No audit firm has been named in connection with the bridge specifically. Decrypt's report, the only outlet covering this as of publication, notes the funds were moved to Ethereum quickly, standard laundering-prep behavior that makes recovery harder the longer it sits unaddressed. Decrypt's report is the only public account so far.
Why the label matters
Calling this an "Arbitrum" hack is doing work it shouldn't. The chain executed correctly. What failed was a bridge AFX chose to build and operate itself rather than route through a more scrutinized, third-party-audited path. That's a decision with consequences: when a protocol runs its own custody rail, it also owns 100% of the attack surface for that rail, with none of the redundant eyes that come from using shared infrastructure. The bounty offer is a tell too. A 30% return offer only makes sense if AFX believes recovery through code or law enforcement is unlikely and negotiation is the fastest path to getting anything back. That's a bet on the attacker's rationality, not a security fix.
The bigger pattern here isn't new: perpetuals DEXs need fast, low-friction collateral movement, and building proprietary bridges is the shortcut many take to avoid third-party integration delays. Ostium's $18 million vault exploit last week and Movement Labs' bankruptcy claims both trace back to variations on the same theme, protocols cutting corners on the plumbing that moves money, not the trading logic itself. Users chasing yield or leverage on newer perp platforms are underwriting infrastructure risk they can't see or price, because none of it shows up in a UI that just says "deposit."
What to watch
The number to track is how much of the $24 million actually comes back, and on what terms. If AFX's 30% offer gets accepted, it tells other protocols that this kind of negotiated settlement is now a viable insurance policy of last resort, which changes the incentive calculus for both sides of future exploits. If it's rejected and the funds sit on Ethereum unmoved for weeks, that's the harder signal: the attacker is waiting out law enforcement rather than negotiating, and AFX's users get nothing back regardless of the offer on the table.
