Arbitrum-based AFX Trade drained of $24 million after bridge keys compromised

The Arbitrum-based protocol AFX Trade lost $24 million after its bridge validator keys were compromised, allowing an attacker to drain the vault. Developers clarified that the underlying Arbitrum network remained secure, as the breach was isolated to the third-party protocol's specific bridge implementation.
Why it matters
This incident underscores the persistent security risks associated with cross-chain bridges and the importance of key management in decentralized finance.
Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said the Arbitrum native bridge "has not been hacked or exploited in any way" and that the transaction originated from a third-party protocol.
A hack of Arbitrum's own bridge would signal risk across the entire layer-2 network, but a compromised protocol running on top of it is a contained failure.
Nothing in the bridge's own code logic was broken. Bridges are a blockchain-based tool to transfer tokens between various networks, including ones they were not initially supported on.
Security firm Blockaid said the on-chain logic was not bypassed. Instead, five of the bridge's hot-validator signatures, the approvals that authorize a withdrawal, signed off on moving 24,150,000 USDC to the attacker's wallet, clearing the roughly two-thirds quorum the bridge requires.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in