AFX Trade Offers $7.2M Bounty to Recover 70% of Stolen $24.15M in USDC

iconCryptoBriefing
Share
AI summary iconSummary
AFX Trade, a decentralized exchange on Arbitrum, was hacked on July 22, 2026, losing $24.15 million in USDC via a bridge attack. The exchange is offering a $7.2 million bounty for the return of 70% of the funds, letting the attacker keep 30%. The exploit targeted off-chain validator signing keys, not smart contracts or Arbitrum’s infrastructure. The attack happened during a surge of hacks totaling over $35 million in two days and nearly $97 million in July 2026. Proof of Work (PoW) and Proof of Stake (PoS) systems remain under scrutiny as security threats rise.

AFX Trade, a decentralized exchange running on Arbitrum, just lost $24.15 million in USDC through a bridge attack. And now it’s essentially negotiating with the person who robbed it, offering them roughly $7.2 million to give the rest back.

The white-hat bounty deal, proposed publicly by AFX head of growth Ken C, would let the attacker keep 30% of the stolen funds as a “bounty” in exchange for returning the remaining 70%.

Advertisement

What actually happened

The exploit hit on July 22, 2026, targeting AFX Trade’s custody bridge rather than its smart contracts or Arbitrum’s underlying infrastructure. The attacker compromised off-chain validator signing keys.

Once inside, the attacker drained approximately $24.15 million in USDC from the bridge. They then moved the funds to Ethereum and swapped them for about 12,467 ETH, which was trading at roughly $1,937 per token at the time. AFX suspended its bridge immediately after discovering the breach.

Security firms Blockaid and PeckShield both confirmed the attack and were quick to note that Arbitrum’s native bridge remained completely unaffected.

Part of a much bigger problem

AFX wasn’t the only victim that week. The exploit was part of a concentrated wave of attacks on July 22 and 23, which collectively resulted in losses exceeding $35 million across multiple platforms. Zoom out further and July 2026 saw nearly $97 million in total hack-related losses, according to data from Blockaid and PeckShield.

The AFX exploit is particularly instructive because it didn’t involve a smart contract flaw. The contracts worked exactly as designed. The weakness was in the off-chain validator key management. Smart contract audits only cover one layer of security. The operational security of key management, validator selection, and bridge architecture often receives far less scrutiny from users, even though it represents a substantial attack surface.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.