AFX Trade, a decentralized perpetuals exchange that settles trades in USDC on Arbitrum, lost approximately $24.15 million on July 22, 2026, after an attacker targeted a bridge the protocol operates. Blockchain security firm Blockaid detected the exploit at 9:30 PM UTC and flagged it publicly within minutes. According to PeckShield, the attacker bridged the stolen funds from Arbitrum to Ethereum and immediately swapped them for 12,467 ETH at an average price of approximately $1,937. Steven Goldfeder, CEO of Offchain Labs, the team behind Arbitrum, confirmed on X that the Arbitrum native bridge was not affected and the exploit originated from a third-party protocol. At the time of writing, AFX Trade had not publicly commented and The Block reported the publication had reached out for response.
July 22, 2026 is now the worst single day for DeFi bridge exploits in 2026. The AFX Trade loss of $24.15 million followed within hours of the Wanchain-Midnight bridge exploit that drained 515 million NIGHT tokens worth approximately $13 million. Two separate bridges, two separate protocols, two separate attack vectors, one day. The combined loss for July 22 is approximately $37 million. For context, that is more than twice the combined losses of the Taiko SGX key exploit and the Polymarket supply chain attack from June.
The AFX Trade exploit is a developing story. Technical details of the attack vector had not been confirmed by any security firm at the time of this article. What is confirmed: the attack was specific to a bridge AFX operates, not Arbitrum’s native bridge infrastructure. Blockaid is working with the Arbitrum team to coordinate response. The stolen funds have already moved from Arbitrum to Ethereum and been converted to ETH, making on-chain tracing the immediate priority.
What We Know and What Is Still Developing
The confirmed facts as of July 22, 2026. Blockaid flagged the exploit at 9:30 PM UTC, describing it as specific to a bridge that AFX Trade operates. PeckShield confirmed the attacker bridged 24.15 million USDC from Arbitrum to Ethereum and swapped it for 12,467 ETH, worth approximately $24 million at the time of the swap. Offchain Labs CEO Steven Goldfeder confirmed the Arbitrum native bridge was not involved. AFX Trade is a USDC-settled derivatives exchange offering perpetual futures on Arbitrum.
What is not yet confirmed: the technical mechanism of the exploit. Blockaid’s initial statement described it as bridge-specific without identifying the root cause. No on-chain forensic analysis comparable to BlockSec Phalcon’s same-day report on the Wanchain-Midnight hack had been published at the time of writing. The attacker’s wallet addresses have not been publicly confirmed by a security firm. No exploit transaction hash has been cited by name in any reporting. This is characteristic of the first two to four hours after a DeFi exploit when on-chain data is visible but analysis is incomplete.
The speed of the fund movement is notable. Bridging $24 million from Arbitrum to Ethereum and swapping it for ETH within the hour of detection is the standard laundering playbook for DeFi exploits: move to a more liquid chain, convert to a less-traceable asset, then route toward mixers or cross-chain hops. The conversion to ETH at $1,937 average means the attacker received roughly 12,467 ETH. At the current ETH price of $1,923 as of July 22, those funds are worth approximately $23.97 million. The swap was near-perfect in execution, suggesting a prepared attacker rather than an opportunistic discovery.
Two Hacks in One Day: The July 22 Context
July 22, 2026: DeFi’s Worst Single Day for Bridge Exploits
Two separate incidents, different protocols, same day | Sources: The Block, CoinTelegraph, TokenPost, CryptoTimes | @cryptonewsbytes
Sources: The Block Jul 22 2026, TokenPost Jul 22, CryptoTimes Jul 21-22, TechTimes Jul 15 | @cryptonewsbytes. Not financial advice.
The two July 22 incidents share the surface characteristic of being bridge exploits, but the known details suggest different attack vectors. The Wanchain-Midnight hack exploited a signed-message encoding flaw in a Plutus V2 smart contract, a technical implementation error in how messages were structured. The AFX Trade exploit is described as bridge-specific but the mechanism is not yet confirmed. The Arbitrum native bridge’s clean record is confirmed in both cases. Both Offchain Labs and the Midnight Foundation issued statements within hours of their respective incidents confirming their core infrastructure was unaffected. The third-party bridge is the common thread.
This is the same pattern CNB has been documenting across every major 2026 DeFi security incident. Ostium’s $18M loss on July 15 was an oracle signer key compromise, infrastructure surrounding the protocol rather than the protocol itself. Taiko’s $1.7M loss in June was a leaked SGX key on GitHub. The Midnight-Wanchain hack was a third-party bridge encoding flaw. In every case, the core protocol and its validators operated normally. In every case, the surrounding infrastructure layer was the entry point. The AFX Trade exploit fits that pattern, though full technical confirmation is pending.
What AFX Trade Is and Why This Matters
AFX Trade describes itself as a derivatives exchange on Arbitrum with USDC settlement. Beyond that, available public information about the protocol is limited. Unlike Ostium, which had raised $27.8 million from named institutional backers including General Catalyst and Jump Crypto and had a well-documented product history, AFX Trade’s investor base and total value locked had not been widely reported before this incident. The $24.15 million in drained USDC represents the total loss, but without TVL data it is not possible to characterize what percentage of the protocol’s assets were taken.
The significance is not protocol-specific. It is structural. Two bridge exploits in one day, both on protocols built on Arbitrum, both targeting third-party bridge infrastructure rather than Arbitrum itself, on a day when the broader crypto market was watching the CLARITY Act Senate floor vote and BTC was trading at $65,900, illustrates the gap between where institutional DeFi attention is focused and where DeFi security is actually failing. Institutional capital is assessing regulatory frameworks. The infrastructure those institutions would use to move assets across chains is failing at the rate of multiple incidents per week in July 2026.
Arbitrum’s native bridge has maintained its clean record through both today’s incidents. Offchain Labs was transparent and fast in both confirmations. The third-party bridge layer, which Arbitrum does not control and which any external team can build and operate on the network, is where the losses are occurring. That distinction matters for the network’s long-term institutional credibility but it does not change the reality that $37 million left the Arbitrum ecosystem today through infrastructure that users reasonably expected to be safe.
Frequently Asked Questions
Is Arbitrum’s native bridge safe after these exploits?
Yes. Offchain Labs CEO Steven Goldfeder confirmed the Arbitrum native bridge was not involved in the AFX Trade exploit. The same was true of the Wanchain-Midnight incident earlier today, where Wanchain’s bridge is a third-party deployment on the Cardano-BNB Chain corridor rather than the Arbitrum native bridge. Both exploits targeted application-layer bridges built by external teams, not Arbitrum’s core cross-chain infrastructure.
What is the difference between Arbitrum’s native bridge and a third-party bridge?
Arbitrum’s native bridge is the official Offchain Labs-built infrastructure for moving assets between Arbitrum and Ethereum, secured by the rollup’s fraud-proof system. Third-party bridges are independently built products that operate on Arbitrum but are developed and maintained by external teams using their own smart contracts, validator sets, and message-passing systems. Third-party bridges can offer additional functionality, including cross-chain routes to networks other than Ethereum, but they carry their own security assumptions separate from Arbitrum’s core infrastructure.
How does this relate to the Ostium hack on July 15?
These are separate incidents. The Ostium hack on July 15 involved a compromised oracle signer key that allowed an attacker to submit future-dated price data and trigger $18-24 million in fraudulent payouts from Ostium’s liquidity vault. The AFX Trade exploit on July 22 targeted a bridge AFX operates. The connection is thematic: both are Arbitrum-based protocols, both involved infrastructure surrounding the core protocol rather than Arbitrum itself, and both were detected by Blockaid’s real-time monitoring. The attack mechanisms are different.
Further Reading
The July 15 Arbitrum incident. Same Blockaid detection, different mechanism: oracle signer key compromise rather than bridge exploit.
The other July 22 bridge exploit. Wanchain-Midnight, $13M, signed-message encoding flaw. Full technical breakdown of the day’s first major incident.
This article is for informational purposes only and does not constitute financial advice. Sources: The Block Jul 22 2026 (Timmy Shen), CoinTelegraph Jul 22 2026, Blockaid X post July 22 2026, PeckShield X post July 22 2026, Offchain Labs CEO Steven Goldfeder X post July 22 2026, Lookonchain Jul 22 2026, CoinSpectator Jul 22 2026. Published July 22, 2026.

