πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
Blockchain

AFX Trade Loses $24.15M After Five of Seven Keys Fall

22 Jul 2026by CryptoJazz Admin1 min read6 views
AFX Trade Loses $24.15M After Five of Seven Keys Fall

AFX Trade, a trading protocol built on Arbitrum, halted its cross-chain bridge on Wednesday after an attacker withdrew $24.15 million in USDC from it. The code was not broken: the attacker held the private keys to five of the seven validators that authorize the bridge's transfers, a compromise that happened entirely off-chain. The stolen USDC was moved to Ethereum and swapped into 12,467.5 ETH, which sat in a single wallet. AFX said trading infrastructure was unaffected, and the Arbitrum network itself was not involved. The Block and the security firm BlockSec both dated the exploit to 22 July; no funds had been returned.

The Threshold: Seven Validators, 6,667 Votes and a 200-Second Window

A bridge of this kind does not so much move assets between chains as attest to them. An independent set of validators watches a deposit on one chain and signs a message authorizing the matching release on the other, and that signing power is split across several parties — a multi-signature, or multisig, arrangement — so no single compromised machine can approve a withdrawal by itself. AFX weighted its validators in voting units and required 6,667 of them to authorize a transfer. The five validators whose keys the attacker obtained carried 7,142 units between them, clearing that bar without help. That is why five of seven is the number that matters: once the threshold is met, the two honest validators have no vote left to cast that could stop anything.

The one control still standing was time. The bridge held an authorized transfer for a 200-second dispute window before executing it, a delay meant to give operators a chance to notice something wrong and intervene. Those 200 seconds elapsed and the transfer settled. The failure sat in key custody rather than in contract code, the same category as June's Humanity Protocol drain, in which multisig keys meant for four separate people ended up on one compromised device during setup.

The Money: $24.15 Million in USDC, Consolidated Into 12,467.5 ETH

The full amount left in USDC, a dollar-pegged stablecoin, was bridged to Ethereum and swapped into 12,467.5 ETH held at a single address. Consolidating into one asset at one address is the usual shape of these drains, since it leaves the attacker holding something an issuer cannot freeze the way a stablecoin balance can. AFX stopped bridge operations immediately. The incident lands in a month already heavy with bridge losses, among them the 515.2 million NIGHT drained from Wanchain's Cardano bridge two days earlier and the $1.65 million taken from Allbridge Core on 19 July. Those two were coding failures; this one was not.

The Offer: 30% for the Attacker If 70% Comes Back

AFX's leadership, in the person of an executive identified as Ken C, publicly offered the attacker a white-hat settlement: keep 30% of the proceeds, return the other 70%, with the offer available only for a limited time. Plainly stated, that is a payment of roughly $7.2 million at the value taken, made to the party that took it, in the hope of recovering the rest. Offers structured this way have become a pattern over the past few weeks: the lending protocol Bonzo Lend saw a similar outcome on 11 July, when a second wallet involved in its oracle exploit identified itself as a white-hat responder and indicated it would send back about $1 million. The security firm PeckShield has described the 30% split as hardening into a de facto industry practice, even though how such payments should be classified in law remains unsettled.

What Is Unresolved: How Five Sets of Keys Came Into One Pair of Hands

The disclosure so far explains what the keys did, not how they were obtained, and that answer matters more than the arithmetic of the threshold. Five separate validators falling together points at something shared — common infrastructure, a common operator, a common backup — rather than five independent break-ins, and until AFX publishes the detail, other operators cannot check whether they run the same arrangement. The narrower questions are whether the bridge reopens, on what validator set, and whether a 200-second dispute window counts as a control at all once the signing threshold has been cleared. Users are waiting on both a post-mortem and any response to the settlement offer.

Read also: Singapore's Triple-A Has Its Hot Wallets Drained

← All news