Key Takeaways: AFX Trade lost $24.15M USDC on July 22 after an attacker exploited its cross-chain bridge on Arbitrum — July's 14th crypto hack.
Key Takeaways: AFX Trade lost $24.15M USDC on July 22 after an attacker exploited its cross-chain bridge on Arbitrum — July's 14th crypto hack.

AFX Trade lost $24.15M USDC on July 22 after an attacker exploited a bridge the protocol operates on Arbitrum, security firm Blockaid said. AFX Trade is a decentralized exchange and cross-chain bridge protocol that facilitates asset transfers between Ethereum and Arbitrum networks.
"Blockaid detected the drain at 21:30 UTC and began coordinating a response with the Arbitrum team," the security firm said. Steven Goldfeder, co-founder of Offchain Labs, drew a firm line between AFX's bridge and Arbitrum's core infrastructure. "We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way," he said.
The attacker moved the stolen USDC from Arbitrum to Ethereum and swapped it into 12,467.5 ETH, according to PeckShield. The funds were traced to wallet 0x6276...ebAC. The tally reflects funds drained so far and could still shift as the flow is tracked.
The exploit pushes July's total crypto hack losses to roughly $97M across 14 incidents, surpassing June's $75.32M, according to DefiLlama data. The coming days should reveal whether AFX Trade can freeze or recover any of the stolen funds.
The AFX breach is the latest in a costly stretch for the sector. Data from DefiLlama showed 13 hacks across various protocols in July prior to this incident, totaling $72.6M in losses. The AFX exploit brings the count to 14 and pushes the July total to roughly $97M — already exceeding the $75.32M in losses from June.
The exploit follows a pattern of cross-chain attacks that have drained protocols through their bridge layers. Earlier on July 22, 42DAO's Balance Coin stablecoin lost its dollar peg after an oracle attack drained $915K from the protocol on BNB Chain, according to PeckShield and SlowMist. Earlier in July, Bonzo Finance on Hedera lost $9.05M in an oracle exploit, and Ostium on Arbitrum lost $18M after an attacker compromised an oracle signer key. The two incidents on the same day show that DeFi infrastructure layers — bridges and oracles — remain the primary attack surface, rather than smart contract code logic.
For AFX Trade users, the immediate question is whether the protocol can freeze or recover the stolen funds. The attacker's movement of assets from Arbitrum to Ethereum suggests an intent to further obfuscate the trail, potentially through coin mixing services. The broader DeFi ecosystem faces renewed scrutiny as July's incident count and total losses outpace the prior month, with no sign of the attack frequency slowing.
This article is for informational purposes only and does not constitute investment advice.