Skip to content
Est. MMXXVIVol. VI · № 316RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 314Private Key Compromise

AFX Trade Bridge Key Compromise

Attackers social-engineered an AFX Trade developer, seized 5 of 7 bridge validator keys, and drained $24.15M in USDC from the Arbitrum perp DEX.

Date
Victim
AFX Trade
Status
Funds Stolen
Attribution
Lazarus Group / UNC4899 (DPRK)

On July 22, 2026, AFX Trade, an Arbitrum-based decentralized perpetuals exchange, was drained of approximately $24.15 million in USDC after attackers compromised the private keys controlling its cross-chain bridge. It was the largest of three protocol exploits that struck within roughly six hours on July 22–23, and forensic analysts attributed it to UNC4899 / TraderTraitor, a North Korean state-linked group also associated with the Lazarus Group.

What happened

AFX's bridge operated a seven-validator multisignature scheme with 10,000 voting units distributed unequally across the validators. Authorizing a transfer required 6,667 units. Rather than break the cryptography, the attackers went after the people who held the keys.

  • Beginning around July 9, an operative posing as a recruiter from a fictitious firm ("Oddium Lab") ran a social-engineering campaign against an AFX developer.
  • Through that access, the attackers ultimately obtained the signing keys for five of the seven validators, controlling roughly 7,142 voting units — comfortably above the 6,667-unit threshold.
  • With a valid quorum in hand, they signed a single malicious withdrawal that moved about $24.15 million in USDC to an attacker-controlled address.
  • The stolen USDC was bridged to Ethereum and swapped into roughly 12,467.5 ETH, a laundering pattern consistent with DPRK-affiliated operations.

Aftermath

  • AFX publicly offered the attacker a white-hat settlement: return 70% of the funds and keep 30% as a bounty. The offer was posted to AFX's X account and delivered as an on-chain message to the attacker's wallet.
  • No public report has confirmed the return of any portion of the stolen assets.
  • On August 3, 2026, AFX published a goodwill recovery plan for affected users.
  • The attribution to UNC4899 places AFX alongside a run of 2026 losses tied to North Korean operators, including the Drift Protocol exploit earlier in the year.

Why it matters

AFX is a textbook case of the dominant 2026 attack pattern: the keys, not the code, are the attack surface. A multisig is only as strong as the humans who hold its shares, and a validator quorum assembled through phishing produces transactions that are cryptographically valid and therefore unstoppable on-chain.

The incident echoes the Ronin Bridge hack, where Lazarus similarly compromised a majority of validator keys rather than exploiting a contract bug. It also arrived the same day as the B² Network upgrade-authority compromise and one day before the Verus-Ethereum bridge repeat exploit — three separate teams losing funds to compromised keys and permissions within hours, underscoring that operational security, hardware-backed key custody, and validator diversity now matter as much as smart-contract audits.

Sources & on-chain evidence

  1. [01]coindesk.comhttps://www.coindesk.com/tech/2026/07/23/arbitrum-based-afx-trade-drained-of-usd24-million-after-bridge-keys-compromised
  2. [02]halborn.comhttps://www.halborn.com/blog/post/explained-the-afxbridge-hack-july-2026
  3. [03]decrypt.cohttps://decrypt.co/374133/arbitrum-perp-dex-afx-trade-drained-of-24m-offers-hacker-30-to-return-it
  4. [04]kucoin.comhttps://www.kucoin.com/blog/afx-bridge-hack-arbitrum-usdc-exploit

Related filings