$24M USDC Drained from Arbitrum Bridge in AFX Protocol Exploit
An exploit targeting AFX's self-operated custody protocol on July 22, 2026, drained roughly $24.15 million in USDC from the Arbitrum bridge.
The security firm Blockaid flagged the incident at 21:30 UTC and reported that the attacker withdrew funds with 5 signatures from a 7-validator set, suggesting a possible validator key or backend compromise.
AFX confirmed the incident in an official statement, suspending protocol operations and working with outside blockchain security partners to investigate the root cause.
The company assured that the trading infrastructure, mainnet, and Arbitrum network have not been compromised, and its native token ARB showed a mild pullback following the incident.




