Offchain Labs CEO Steven Goldfeder drew a sharp line between native and third-party bridge security after a $24.15 million exploit on Arbitrum.
Third-party bridges introduce their own trust assumptions and validator sets that native bridges do not carry, Goldfeder, who holds a Ph.D. in applied cryptography from Princeton University, said.
The breach hit AFX Trade on July 22, when attackers compromised validator keys on the bridge protocol and drained approximately $24.15 million in USDC. The stolen funds were subsequently swapped for roughly 12,467 ETH. Goldfeder confirmed the exploit originated entirely from a third-party protocol and that Arbitrum's native bridge remained secure throughout the incident. AFX Trade proposed a white-hat bounty deal to the attacker: return 70 percent of the stolen funds and keep the rest as a bug bounty.
The distinction between native and third-party bridges carries real consequences for users moving assets between Ethereum and Arbitrum. Arbitrum's native bridge inherits its security from the rollup's architecture, which ultimately relies on Ethereum's own security guarantees. Third-party bridges like AFX Trade operate independently, introducing their own key management practices and validator sets. The incident was far from isolated — July 2026 has seen at least 14 recorded security breaches across the crypto sector, according to security firms tracking the period. Blockaid recorded more than $1 billion in crypto exploit losses in the first half of 2026, with DPRK-linked hackers responsible for nearly $600 million of that total through two major exploits targeting the Drift and KelpDAO protocols. The steady drumbeat of bridge exploits gives regulators ammunition to impose stricter guidelines on bridging technology and cross-chain protocols, Goldfeder said.
This article is for informational purposes only and does not constitute investment advice.