On July 22, 2026, AFX Trade, an Arbitrum-based decentralized perpetuals exchange, was drained of approximately $24.15 million in USDC after attackers compromised the private keys controlling its cross-chain bridge. It was the largest of three protocol exploits that struck within roughly six hours on July 22–23, and forensic analysts attributed it to UNC4899 / TraderTraitor, a North Korean state-linked group also associated with the Lazarus Group.
What happened
AFX's bridge operated a seven-validator multisignature scheme with 10,000 voting units distributed unequally across the validators. Authorizing a transfer required 6,667 units. Rather than break the cryptography, the attackers went after the people who held the keys.
- Beginning around July 9, an operative posing as a recruiter from a fictitious firm ("Oddium Lab") ran a social-engineering campaign against an AFX developer.
- Through that access, the attackers ultimately obtained the signing keys for five of the seven validators, controlling roughly 7,142 voting units — comfortably above the 6,667-unit threshold.
- With a valid quorum in hand, they signed a single malicious withdrawal that moved about $24.15 million in USDC to an attacker-controlled address.
- The stolen USDC was bridged to Ethereum and swapped into roughly 12,467.5 ETH, a laundering pattern consistent with DPRK-affiliated operations.
Aftermath
- AFX publicly offered the attacker a white-hat settlement: return 70% of the funds and keep 30% as a bounty. The offer was posted to AFX's X account and delivered as an on-chain message to the attacker's wallet.
- No public report has confirmed the return of any portion of the stolen assets.
- On August 3, 2026, AFX published a goodwill recovery plan for affected users.
- The attribution to UNC4899 places AFX alongside a run of 2026 losses tied to North Korean operators, including the Drift Protocol exploit earlier in the year.
Why it matters
AFX is a textbook case of the dominant 2026 attack pattern: the keys, not the code, are the attack surface. A multisig is only as strong as the humans who hold its shares, and a validator quorum assembled through phishing produces transactions that are cryptographically valid and therefore unstoppable on-chain.
The incident echoes the Ronin Bridge hack, where Lazarus similarly compromised a majority of validator keys rather than exploiting a contract bug. It also arrived the same day as the B² Network upgrade-authority compromise and one day before the Verus-Ethereum bridge repeat exploit — three separate teams losing funds to compromised keys and permissions within hours, underscoring that operational security, hardware-backed key custody, and validator diversity now matter as much as smart-contract audits.
Sources & on-chain evidence
- [01]coindesk.comhttps://www.coindesk.com/tech/2026/07/23/arbitrum-based-afx-trade-drained-of-usd24-million-after-bridge-keys-compromised
- [02]halborn.comhttps://www.halborn.com/blog/post/explained-the-afxbridge-hack-july-2026
- [03]decrypt.cohttps://decrypt.co/374133/arbitrum-perp-dex-afx-trade-drained-of-24m-offers-hacker-30-to-return-it
- [04]kucoin.comhttps://www.kucoin.com/blog/afx-bridge-hack-arbitrum-usdc-exploit