AFX Commerce has paused its Arbitrum-operated USDC custody bridge after roughly $24.15 million in USDC was drained on July 22, 2026, in keeping with a Blockaid alert. The incident was detected at 21:30 UTC, focusing on AFX’s bridge infrastructure fairly than Arbitrum’s native bridge. The precise root trigger stays underneath investigation by the mission, whereas safety corporations monitor the movement of stolen funds to help restoration efforts.
AFX Pauses Bridge After $24.15M USDC Drain
AFX confirmed an incident involving its AFX-operated USDC custody bridge on Arbitrum, which handles USDC deposits/withdrawals for the mission’s buying and selling ecosystem. Instantly upon detecting the incident, AFX said it paused bridge operations and activated its incident response procedures.
AFX is conscious of an incident involving the AFX-operated USDC custody bridge on Arbitrum.
Upon detecting the incident, we instantly suspended bridge operations and initiated our incident response procedures. Our engineering and safety groups are actively investigating the basis…— AFX Commerce (@AFX_XYZ) July 23, 2026
Preliminary assessments point out the incident seems remoted to the project-operated custody bridge. AFX said that its buying and selling infrastructure, AFX mainnet, and the Arbitrum community weren’t compromised.
Offchain Labs shared an identical message. Steven Goldfeder, co-founder and CEO of Offchain Labs, said that the related transaction originated from a third-party protocol, whereas Arbitrum’s native bridge was neither hacked nor exploited. This data additional signifies that the injury was targeting AFX’s bridge, although the dimensions of the loss for the mission stays substantial.
Funds Stream to Ethereum
Blockaid reported that the exploit was detected at 21:30 UTC on July 22, 2026, with roughly $24.15 million in USDC drained from the AFX-operated bridge. This determine nearly matches AFX Bridge’s pre-incident TVL. DefiLlama information logged AFX Bridge with round $24.18 million in TVL, all located on Arbitrum, representing almost the whole lot of the locked belongings within the bridge.
After draining the USDC, the attacker transferred the belongings from Arbitrum to Ethereum. PeckShield tracked the funds movement, noting that the stolen USDC was subsequently swapped into roughly 12,467.5 ETH. This ETH was traced again to pockets 0x6276…ebAC.
Attacker pockets holding swapped ETH. Supply: PeckShield
USDC is a stablecoin issued by Circle and could be frozen on the token contract stage underneath sure circumstances. ETH lacks an identical mechanism, so as soon as belongings are swapped and consolidated into an Ethereum pockets, restoration depends extra closely on on-chain monitoring and alternate coordination.
AFX Works to Get well Funds
AFX said it’s working with blockchain safety companions because the investigation continues. In the meantime, SlowMist famous that the stolen funds stay within the attacker’s tackle, which has been reported to the Crypto Protection Alliance (CDA)—a collaborative community of exchanges and ecosystem companions. AFX stated the related tackle is being monitored by ecosystem stakeholders.
The mission additionally talked about that Zellic, the agency that beforehand audited the bridge code, has been invited to help within the investigation. A technical postmortem from AFX and safety corporations will function the idea to find out whether or not the incident concerned code vulnerabilities, validator setup, key administration, or backend signing flows.
In parallel with the investigation, AFX amplified a white-hat settlement provide from Ken / Supercube, Head of Development at AFX. The provide requests the occasion accountable for the bridge incident to return 70% of the stolen belongings to deal with 0x222B…9f1B, whereas retaining the remaining 30% as a white-hat bounty.
We’re extending a white hat settlement provide to the occasion accountable for the latest bridge incident.
Return 70% of the stolen belongings to the next tackle:
0x222Bd8dbc0d71972f880DAb5D69cdCFD903D9f1BChances are you’ll retain the remaining 30% as a white hat bounty.
Our precedence is…
— Ken / Supercube🧊 (@supercubeguy) July 23, 2026
AFX’s restoration messaging at the moment focuses on two aims: defending the group and maximizing the potential restoration of person belongings. Nonetheless, on the time of writing, there isn’t a public affirmation that any portion of the stolen funds has been returned.
Root Trigger Nonetheless Below Investigation
AFX has not but introduced the ultimate assault vector. In official updates, the mission solely said that the investigation is ongoing and that additional data might be offered as verified information turns into out there. Due to this fact, there may be at the moment no foundation for a definitive conclusion on whether or not this was a wise contract exploit or a validator key compromise, past assessments from safety sources.
However, a number of safety sources and DeFi information aggregators have categorized the occasion as an infrastructure incident. SlowMist described it as an exploit focusing on AFX’s cross-chain/USDC custody bridge on Arbitrum, suggesting the attacker used compromised validator sizzling keys to attain a payout quorum. The DefiLlama Hacks database additionally recorded a $24.15 million loss for AFX Bridge, classifying it as “Infrastructure” with the method labeled “Non-public Key Compromised.”
If the postmortem confirms this classification, the AFX incident will function one other instance of operational dangers on the bridge layer, together with signing keys, validator setups, custody processes, and withdrawal verification mechanisms. Bridges usually maintain massive asset volumes in contracts or custody layers, making procedural flaws in verification able to inflicting concentrated losses.
AFX has not disclosed the variety of affected keys or validators, the particular position of the bridge code, or person reimbursement plans. The mission has additionally not confirmed any restoration from the stolen funds. The ultimate technical root trigger stays pending verification from AFX and investigative groups.

