VERSE PRESS

Crypto News, Global First.

AFX Trade Loses $24 Million in Bridge Exploit, Funds Moved to Ethereum

Arbitrum-based perpetual futures protocol drained in early hours of July 23; security firms flag the attack and track stolen assets in real time.

|

A decentralized derivatives platform lost roughly $24 million on Thursday after an attacker exploited a vulnerability in its bridge infrastructure. AFX Trade is a sovereign Layer 1 blockchain and perpetual futures exchange (a platform that lets users trade price contracts without holding the underlying asset) that integrates with the Arbitrum network for user deposits, making the bridge a core part of its architecture and a natural attack surface. The stolen funds were moved from Arbitrum to Ethereum mainnet and converted to ETH shortly after the attack. Security firm Blockaid flagged the exploit while blockchain analytics firm PeckShield tracked the resulting on-chain activity.

According to PeckShield, the attacker received approximately 12,467 ETH after swapping the drained funds. At the time of the swap, that figure accounted for the full roughly $24 million loss reported by The Block, which first published details of the incident at 01:39 UTC. The specific technical vulnerability used in the attack had not been publicly confirmed as of this writing. The attack vector in bridge exploits typically falls into one of four categories: forged cross-chain messages, missing source-amount validation in bridge contracts, compromised validator or oracle keys, or flawed single DVN (Decentralized Verifier Network) configuration, according to reporting from CryptoTimes, the 1inch Blog, and CryptoBriefing. No official statement from the AFX team had been published by the time this article was filed.

The timing of the attack fits a pattern that has accelerated throughout 2026. Bridge-related losses across the industry exceeded $328 million through May 2026, spread across at least 14 major incidents, according to reporting from CryptoTimes and the 1inch blog. Total crypto hack losses in the first half of 2026 reached $750 million, per PeckShield data cited by the Bitcoin Foundation. The AFX incident comes just eight days after Ostium, another Arbitrum-based perpetual DEX, was drained of a sum reported in a range of approximately $18 million to $24 million through a compromised oracle signer key. In that case, an attacker manipulated the reported Bitcoin price to trigger fraudulent payouts, then converted the proceeds to approximately 12,085 ETH. PeckShield noted in its half-year report that stolen funds in multiple 2026 exploits have been mixed together, suggesting a possible connection between perpetrators, though that observation draws on broader industry data and is not specific to the AFX incident. The report cited fund movements following the Kelp DAO hack (a $292 million incident in April) as one example. The near-identical ETH amounts in the Ostium and AFX attacks are worth noting, though no confirmed link between the two incidents has been established.

AFX Trade operates a liquidity vault called ALP that accepts deposits from any user and pays 0% management fees. In comparable exploits this year, liquidity providers have absorbed the majority of losses. When Ostium was drained, roughly 28 percent of its $63 million liquidity pool was wiped out. AFX's vault design follows a similar open model, meaning retail depositors who provided liquidity to the protocol may face direct losses. The protocol supports up to 100x leverage on USDC-margined contracts across crypto, commodities, equities, and ETFs, with a bridge to Arbitrum serving as the primary deposit pathway for user funds.

The regional implications of this exploit are significant. India currently ranks first globally in crypto adoption, Nigeria second, and Pakistan eighth, according to the 2026 Global Crypto Adoption Index. All three countries have large retail user bases on decentralized derivatives platforms, partly because regulatory restrictions and dollar-denominated account minimums make centralized futures exchanges inaccessible to many traders. In Sub-Saharan Africa, Ethiopia, Kenya, and Ghana each appeared in the global top 20 adoption rankings for the first time this year. The same index notes that Arbitrum and other Layer 2 networks are now tracked as part of its DeFi sub-indexes, confirming that users in these markets are active on the precise infrastructure targeted in this attack. Stablecoin volumes in Sub-Saharan Africa grew 180 percent year over year, with much of that activity running through Layer 2 networks. USDC losses in a protocol like AFX do not affect just one group of traders. They erode confidence in stablecoin-based DeFi tools that serve as savings and remittance instruments in markets where traditional banking access is limited.

Developers building on Arbitrum should treat bridge contracts as high-priority attack surfaces requiring independent audits, multi-signature controls, and automated circuit breakers that can pause withdrawals if anomalous outflows are detected, per guidance from security auditors including QuillAudits. Users should be cautious about concentrating funds in liquidity vaults on protocols that have not published recent security audits. Verse Press will update this article when AFX Trade releases an official post-mortem or when Blockaid or PeckShield publish a detailed technical breakdown of the attack vector.

Primary source: The Block. On-chain data: PeckShield. Exploit detection: Blockaid. Regional adoption data: Crypto News Navigator / 2026 Global Crypto Adoption Index.