In July 2026, AFX Trade, an Arbitrum-based decentralized perpetuals exchange, was the victim of a $24 million hack. The attacker targeted the protocol’s cross-chain bridge, gaining the required access through compromised private keys.
Inside the Attack
The AFX Bridge operates a 7-validator multisignature scheme with 10,000 voting units distributed (unequally) across these validators. Under this protocol, two-thirds of the voting units need to approve a transaction for it to be executed.
The root cause of the AFX Bridge hack was compromised private keys. The attacker managed to gain access to the private keys of five of the protocol’s seven validators. In total, these validators controlled 7,142 voting units, well over the 6,667 needed to authorize a transaction.
After the attacker gained access to these keys, they used them to perform a malicious transaction that transferred about $24.15 million worth of USDC to an attacker-controlled address. The AFX Bridge has a 200-second dispute window, after which the transaction was successfully executed.
The AFX Bridge hacker transferred the stolen assets to Ethereum, resulting in 12,467.5 ETH being held in a single wallet. In response to the hack, AFX offered a white-hat settlement, allowing the attacker to keep 30% of the stolen assets if they returned the remaining 70%.
Lessons Learned from the Attack
On the surface, AFX was well prepared for this type of hack. The protocol had a multisignature scheme in place, making it more difficult for an attacker to gain access to the keys required to authorize malicious transactions. It also had a dispute period in place, allowing for malicious transactions to be identified and blocked before they could be executed on-chain and became irreversible.
The AFX Bridge hacker didn’t exploit a smart contract vulnerability. The smart contract worked as designed, verifying the transaction’s signatures (which were legitimate) and releasing the funds. The attack was performed entirely off-chain, compromising keys via social engineering, malware, or other means.
This demonstrates the importance of a comprehensive security strategy, considering both the vulnerabilities that can be identified via smart contract security audits and the potential for attackers to exploit off-chain security gaps. Halborn offers Custody and Key Management Assessments to help projects protect private keys and other critical infrastructure and systems with strong security processes and technical controls. To learn more about protecting your project against these types of threats, get in touch with Halborn.
