A glowing blue Ethereum symbol beneath a dark
Crypto

AFX Protocol hit by reported $24.15M bridge exploit as attacker flow turns into ETH buys

Offchain Labs said the incident came from a third-party protocol and Arbitrum’s native bridge was not exploited.

By AI News Crypto Editorial Team7 min read

AFX Protocol, described as a decentralized perpetual exchange on Arbitrum, reportedly lost $24.15 million in an exploit targeting one of its crosschain bridges. On-chain tracking tied the incident to a rapid USDC bridge to Ethereum followed by a large ETH spot purchase, while Offchain Labs said Arbitrum’s native bridge was not compromised.

Key Takeaways

  • AFX Protocol, described as an Arbitrum-based decentralized perpetual exchange, was linked to a reported $24.15 million exploit involving one of its crosschain bridges.
  • Blockaid flagged the exploit at 9:30 p.m. UTC on Wednesday and identified the target as a bridge operated by AFX.
  • The alleged attacker flow bridged 24.15 million USDC to Ethereum and then bought 12,467 ETH at an average price of $1,937.
  • Offchain Labs co-founder Stephen Goldfeder said the transaction originated from a third-party protocol and that Arbitrum’s native bridge was not hacked or exploited.

AFX Protocol Hit by Reported $24.15M Crosschain-Bridge Exploit

AFX Protocol, described as a decentralized perpetual exchange operating on Arbitrum, was tied to a reported $24.15 million loss from an exploit targeting one of its crosschain bridges.

The cleanest hard timestamp in the public trail so far comes from Blockaid, which said it detected the exploit at 9:30 p.m. UTC on Wednesday and that the target was a bridge operated by AFX.

What stands out here is how narrow the confirmed surface area still is. The figure is widely circulated as $24.15 million, but the available details are still mostly third-party detection and on-chain flow interpretation, not a protocol-authored postmortem. For traders, that matters because early exploit narratives often get anchored to a number before the accounting is finalized, and the market tends to price the first credible path of funds rather than the final loss figure.

Attacker Flow: 24.15M USDC to Ethereum, Then 12,467 ETH Bought

The incident immediately stopped being “just” a security headline once the alleged attacker flow showed up as a measurable spot footprint.

Lookonchain said the exploiter bridged 24.15 million USDC to Ethereum and bought 12,467 ETH at an average price of $1,937. Mechanically, that sequence is straightforward: stablecoin liquidity is moved crosschain, then converted into the most liquid base asset on the destination chain.

For a trading desk, the second-order effect is the point. A bridge exploit that ends with a large ETH buy is not neutral to price action in the moment, even if the motive is simply to reposition into an asset that is easier to move, collateralize, or fragment across venues. It is also a reminder that exploit flows can create temporary, non-fundamental demand shocks in spot markets, especially when the asset purchased is deep enough to absorb size without immediately tripping obvious execution constraints.

The other read-through is informational. If the on-chain trail is accurate, the attacker chose Ethereum as the consolidation layer and ETH as the post-bridge inventory. That is a concrete positioning signal traders can monitor for follow-on behavior, because the next actions tend to be the ones that create volatility: further swaps, deposits to centralized exchanges, or additional bridging.

Offchain Labs: Third-Party Protocol Incident, Not Arbitrum’s Native Bridge

Offchain Labs moved quickly to draw a boundary between Arbitrum’s core infrastructure and third-party application risk.

In a post on X, Offchain Labs co-founder Stephen Goldfeder said: “We’re aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third-party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,” emphasizing that Arbitrum’s native bridge was not compromised.

That distinction is not semantics. If the incident is isolated to a third-party bridge operated by an app, the contagion narrative is narrower: it is an AFX-specific bridge risk event, not an Arbitrum-native-bridge event. The pattern worth noting is how quickly “bridge hack on Arbitrum” can be misread as “Arbitrum bridge hack.” Goldfeder’s statement is effectively an attempt to prevent that reflex from turning into broader risk-off positioning across Arbitrum-linked infrastructure.

This does not resolve the AFX situation, but it does set a default assumption for market participants until contradictory evidence appears: treat Arbitrum’s native bridge as out of scope for this specific exploit.

Open Questions: Root Cause, AFX Status, and Whether Funds Can Be Frozen

The story is still developing, and the missing pieces are the ones that determine whether this becomes a contained incident or a longer tail of operational risk.

First, there is no described exploit mechanism in the available details beyond “an exploit targeting one of its crosschain bridges.” Without a root cause, traders cannot yet classify it as a one-off implementation failure, a compromised key scenario, or a broader message-validation issue that might implicate other integrations.

Second, there is no protocol-level statement in the available information from AFX itself on operational status. The immediate questions are basic but market-relevant: whether any contracts or bridges are paused, whether user positions on the perps venue are affected, and whether withdrawals are restricted.

Third, the post-exploit asset path creates a specific monitoring problem. Lookonchain’s account ends with 12,467 ETH bought at an average of $1,937. The next observable steps matter more than the initial buy: any additional swaps, centralized exchange deposits, or further bridging would change the risk profile from “inventory parked” to “inventory in motion.”

Finally, there is the stablecoin control plane. If 24.15 million USDC moved to Ethereum as described, traders will be watching for any issuer or market actions tied to that flow, including blacklisting or freeze attempts. Whether that is feasible depends on where the USDC sits and how it is held, but the presence of a large, identifiable stablecoin leg is one of the few levers that can sometimes alter an attacker’s options.

Bridge Risk Is App-Specific Until Proven Otherwise

I’m treating this as two stories that happen to share a headline.

The first is the reported AFX bridge exploit itself. The facts we have are limited but actionable: a reported $24.15 million loss tied to an AFX-operated bridge, detected by Blockaid at 9:30 p.m. UTC on Wednesday. Until AFX publishes its own accounting and technical details, I consider both the loss figure and the precise scope provisional. That is not cynicism, it is process. Early numbers can be estimates, and early scope can be wrong in both directions.

The second story is the market footprint. Lookonchain’s trace, if accurate, shows the attacker bridged 24.15 million USDC to Ethereum and bought 12,467 ETH at an average of $1,937. That is a clean, measurable flow that traders can monitor without needing to guess at motives. In practice, exploit-driven spot buying can look bullish on a chart while being structurally fragile, because the same inventory can later become sell pressure if it is unwound, hedged, or used as collateral for other exits.

On contagion, Goldfeder’s statement is the key boundary condition. If the transaction originated from a third-party protocol and Arbitrum’s native bridge was not exploited, then the default framing should be “app-specific bridge failure,” not “Arbitrum bridge failure.” The invalidation point is equally clear: any evidence that the native bridge was involved, or that the exploit mechanism generalizes beyond AFX’s bridge implementation, would widen the risk lens immediately.

My base case is containment at the infrastructure narrative level, paired with ongoing uncertainty at the AFX level until the protocol speaks. Confirmation of that thesis looks like two things happening in parallel: Offchain Labs maintains that the native bridge is unaffected as the investigation progresses, and the 12,467 ETH position shows no rapid dispersal into obvious cash-out routes that would amplify market stress.

Sources