AFX Commerce has paused its Arbitrum-operated USDC custody bridge after roughly $24.15 million in USDC was drained on July 22, 2026, in response to a Blockaid alert. The incident was detected at 21:30 UTC, concentrating on AFX’s bridge infrastructure reasonably than Arbitrum’s native bridge. The precise root trigger stays underneath investigation by the challenge, whereas safety corporations monitor the circulation of stolen funds to help restoration efforts.
AFX Pauses Bridge After $24.15M USDC Drain
AFX confirmed an incident involving its AFX-operated USDC custody bridge on Arbitrum, which handles USDC deposits/withdrawals for the challenge’s buying and selling ecosystem. Instantly upon detecting the incident, AFX said it paused bridge operations and activated its incident response procedures.
AFX is conscious of an incident involving the AFX-operated USDC custody bridge on Arbitrum.
Upon detecting the incident, we instantly suspended bridge operations and initiated our incident response procedures. Our engineering and safety groups are actively investigating the basis…— AFX Commerce (@AFX_XYZ) July 23, 2026
Preliminary assessments point out the incident seems remoted to the project-operated custody bridge. AFX said that its buying and selling infrastructure, AFX mainnet, and the Arbitrum community weren’t compromised.
Offchain Labs shared an analogous message. Steven Goldfeder, co-founder and CEO of Offchain Labs, said that the related transaction originated from a third-party protocol, whereas Arbitrum’s native bridge was neither hacked nor exploited. This data additional signifies that the harm was targeting AFX’s bridge, although the size of the loss for the challenge stays substantial.
Funds Move to Ethereum
Blockaid reported that the exploit was detected at 21:30 UTC on July 22, 2026, with roughly $24.15 million in USDC drained from the AFX-operated bridge. This determine virtually matches AFX Bridge’s pre-incident TVL. DefiLlama information logged AFX Bridge with round $24.18 million in TVL, all located on Arbitrum, representing almost the whole thing of the locked property within the bridge.
After draining the USDC, the attacker transferred the property from Arbitrum to Ethereum. PeckShield tracked the funds circulation, noting that the stolen USDC was subsequently swapped into roughly 12,467.5 ETH. This ETH was traced again to pockets 0x6276…ebAC.
Attacker pockets holding swapped ETH. Supply: PeckShield
USDC is a stablecoin issued by Circle and may be frozen on the token contract stage underneath sure circumstances. ETH lacks an analogous mechanism, so as soon as property are swapped and consolidated into an Ethereum pockets, restoration depends extra closely on on-chain monitoring and alternate coordination.
AFX Works to Get better Funds
AFX said it’s working with blockchain safety companions because the investigation continues. In the meantime, SlowMist famous that the stolen funds stay within the attacker’s tackle, which has been reported to the Crypto Protection Alliance (CDA)—a collaborative community of exchanges and ecosystem companions. AFX mentioned the related tackle is being monitored by ecosystem stakeholders.
The challenge additionally talked about that Zellic, the agency that beforehand audited the bridge code, has been invited to help within the investigation. A technical postmortem from AFX and safety corporations will function the premise to find out whether or not the incident concerned code vulnerabilities, validator setup, key administration, or backend signing flows.
In parallel with the investigation, AFX amplified a white-hat settlement provide from Ken / Supercube, Head of Development at AFX. The provide requests the occasion liable for the bridge incident to return 70% of the stolen property to deal with 0x222B…9f1B, whereas retaining the remaining 30% as a white-hat bounty.
We’re extending a white hat settlement provide to the occasion liable for the latest bridge incident.
Return 70% of the stolen property to the next tackle:
0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1BIt’s possible you’ll retain the remaining 30% as a white hat bounty.
Our precedence is…
— Ken / Supercube🧊 (@supercubeguy) July 23, 2026
AFX’s restoration messaging at present focuses on two targets: defending the neighborhood and maximizing the potential restoration of person property. Nonetheless, on the time of writing, there is no such thing as a public affirmation that any portion of the stolen funds has been returned.
Root Trigger Nonetheless Beneath Investigation
AFX has not but introduced the ultimate assault vector. In official updates, the challenge solely said that the investigation is ongoing and that additional data can be offered as verified information turns into obtainable. Subsequently, there may be at present no foundation for a definitive conclusion on whether or not this was a sensible contract exploit or a validator key compromise, past assessments from safety sources.
However, a number of safety sources and DeFi information aggregators have categorized the occasion as an infrastructure incident. SlowMist described it as an exploit concentrating on AFX’s cross-chain/USDC custody bridge on Arbitrum, suggesting the attacker used compromised validator sizzling keys to attain a payout quorum. The DefiLlama Hacks database additionally recorded a $24.15 million loss for AFX Bridge, classifying it as “Infrastructure” with the approach labeled “Non-public Key Compromised.”
If the postmortem confirms this classification, the AFX incident will function one other instance of operational dangers on the bridge layer, together with signing keys, validator setups, custody processes, and withdrawal verification mechanisms. Bridges sometimes maintain massive asset volumes in contracts or custody layers, making procedural flaws in verification able to inflicting concentrated losses.
AFX has not disclosed the variety of affected keys or validators, the particular position of the bridge code, or person reimbursement plans. The challenge has additionally not confirmed any restoration from the stolen funds. The ultimate technical root trigger stays pending verification from AFX and investigative groups.





