CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·

AFX Trade Had a 200-Second Fraud Window. Nobody Filed a Challenge

Five compromised validator keys hit the exact two-thirds quorum needed to empty AFX Trade's Arbitrum bridge. The dispute window was open for 200 seconds. Nobody challenged the withdrawal, and $24.15 million in USDC walked out clean.

S
SYNTH·Hack Database
AFX Trade Had a 200-Second Fraud Window. Nobody Filed a Challenge - CMZ investigation
AFX Trade lost $24.15 million after five compromised validator keys cleared its bridge's quorum.

At 21:30 UTC on July 22, 2026, blockchain security firm Blockaid flagged an alert. AFX Trade, a decentralized perpetuals exchange on Arbitrum, had just been drained of 24,150,000 USDC through its own custodial bridge. The smart contract did not have a bug. It did exactly what it was built to do. That was the problem.

AFX Trade runs a custodial USDC bridge on top of Arbitrum, separate from Arbitrum's own native bridging infrastructure, to move collateral in and out of the exchange. Withdrawals need signatures from a set of seven validators, with roughly two-thirds needed to hit quorum and release funds. Whoever controls enough of those keys controls the bridge.

An attacker got hold of five of the seven validators' signing keys, enough to clear quorum on their own. They authorized a withdrawal of the entire 24,150,000 USDC sitting in the bridge, nearly wiping out AFX Trade's total value locked in a single transaction. The bridge's smart contract had a built-in safeguard, a roughly 200-second window during which anyone could file a dispute and halt a suspicious withdrawal. Nobody filed one. The clock ran out and the contract released the funds automatically, exactly as it was designed to.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

The attacker moved fast. They bridged the stolen USDC from Arbitrum to Ethereum and swapped it for roughly 12,467 ETH at an average price near $1,937, consolidating everything into a single wallet that PeckShield and other trackers have had under watch ever since. Offchain Labs co-founder Steven Goldfeder publicly confirmed Arbitrum's native bridge was never touched. The exploit hit AFX's own infrastructure sitting on top of it.

AFX's head of growth, who goes by Ken C, made the exchange's counter-offer public: give back 70% of the stolen $24.15 million and keep the remaining 30%, about $7.2 million, as a so-called white hat bounty. As of publication, the attacker has not responded and the funds remain untouched in the consolidated wallet.

Security researchers have been warning about exactly this shift for most of 2026. Koinly's mid-year tally found compromised accounts and keys now account for more than half of all DeFi attacks by incident count, overtaking smart contract bugs as the primary cause for the first time. By dollar value the skew is even sharper. The Drift Protocol breach in April, which drained $285 million from a Solana perps platform, followed the same script: months of quiet access to privileged credentials, then one fast withdrawal once the attacker was ready to move.

AFX Trade's bridge was not the only one hit that day. Blockaid tagged the July 22-23 stretch "Hackers' Day" after three separate exploits landed within roughly seven hours of each other. A hacker reused a vulnerability from May 2026 to pull $7.54 million from the Verus-Ethereum bridge, and a third exploit hit BSquared. Combined losses across all three crossed $35.5 million in under a day, and Blockaid's running tally put total July 2026 hack losses at nearly $97 million. Blockaid classified the second quarter of 2026 among the worst on record for hack activity even before AFX and Ostium were added to the count, and the run of back-to-back Arbitrum-based exploits has traders questioning whether the network's growing web of independently operated bridges is outpacing anyone's ability to secure them.

AFX's exploit landed exactly one week after Ostium, another Arbitrum-based perpetuals exchange, lost up to $24 million of its own to a compromised oracle key. Two nine-figure-adjacent bridge and oracle failures on the same network in the same week, and neither one involved a single flawed line of Solidity. The pattern security researchers have been describing all year held again: attackers are no longer trying to outsmart the code. They are going after whoever holds the keys to it.

The Aftermath

The stolen funds remain in the attacker's consolidated wallet, untouched since the swap into ETH. AFX Trade's public 70/30 return offer has gone unanswered. The exchange paused its custodial bridge immediately after the exploit and has not announced a timeline for reopening it or a compensation plan for affected users. Blockaid and PeckShield continue monitoring the wallet for any movement.

LESSONS LEARNED

!A 200-second dispute window only works if someone is watching closely enough to use it. AFX Trade had the safeguard built in and it fired blank.
!Quorum systems are only as strong as the number of keys an attacker needs to compromise. Five out of seven turned out to be an achievable number.
!Public bounty offers after the fact are a Hail Mary, not a security strategy. AFX asked nicely for 70% back. The attacker didn't answer.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database