Koinlytics

AFX Trade Called Its Bridge A Multi-Sig. Five Hot Keys Signed $24.15M Of USDC Out In One Transaction

Jul 23, 2026ETHUSDCARBafx-tradearbitrumbridge-exploitpeckshieldblockaidvalidator-keys
AFX Trade lost $24.15M USDC after five hot validator keys cleared the bridge's 2/3 quorum and authorized a single transfer. Funds were bridged to Ethereum and swapped for roughly 12,467 ETH. Arbitrum's native bridge was untouched.

AFX Trade, a perpetual DEX built on Arbitrum, was drained of $24,150,000 in USDC on July 23, 2026. The attacker did not exploit a smart contract bug in AFX's perpetuals engine, did not compromise Arbitrum's native canonical bridge, and did not find a novel cryptographic flaw. What they did was simpler and more instructive: they obtained five hot signing keys belonging to validators of the third-party bridge AFX had chosen to operate on Arbitrum, and those five signatures were enough to clear the roughly two-thirds quorum the bridge required to authorize an outbound transfer. One signed message. $24.15M gone. The USDC was moved to Ethereum through the same bridge's outbound path, then swapped for approximately 12,467 ETH, implying an execution price near $1,935 per ETH. Blockaid flagged the outflow in near-real-time and PeckShield published the post-mortem inside the hour.

The mechanism, function by function

The bridge AFX used is a lock-and-mint design with an off-chain validator set. Deposits on Ethereum lock USDC in a vault contract; the validator set observes the deposit, produces signatures, and a mint function on Arbitrum releases the wrapped representation to the depositor. The outbound path runs in reverse: a burn on Arbitrum, signatures from the validator set, and a release from the Ethereum vault. Release is gated by a threshold verification that counts valid validator signatures against a stored quorum parameter. The attacker acquired five hot keys, likely from a shared operational surface such as a signing service, HSM proxy, or CI environment where multiple validators kept signing material warm for latency reasons. They constructed a single valid release message for 24,150,000 USDC, attached the five signatures, submitted it, and the contract did exactly what it was written to do.

Why hot-signature quorums fail this way

A 5-of-N with a two-thirds threshold reads like a multi-sig on paper. In practice, if the keys sit on machines that share operators, share deployment pipelines, share cloud accounts, or share a single monitoring plane, the effective attack surface collapses to the weakest of those shared components. Multi-signature security assumes independence of failure. Hot keys operated by a single team, on infrastructure they all authenticate into, are not independent. They are one key wearing five hats. The quorum arithmetic gives the illusion of decentralized custody while the operational reality is closer to a single point of failure with extra signature bytes.

Third-party bridges are not native L2 bridges

Arbitrum's canonical bridge inherits security from Ethereum through the rollup's fraud-proof and data-availability guarantees. A third-party bridge does not. It inherits security from whatever trust assumption its validator set embodies, and that assumption is external to the L2's security model. When a protocol lists TVL on Arbitrum but routes deposits through a non-canonical bridge, the depositor is holding a claim against the bridge operator, not against Arbitrum. The rollup can be functioning perfectly while the bridge is being emptied, which is exactly the state AFX was in for the duration of the exploit.

What to check before depositing

Before allocating to any protocol on an L2 or sidechain, verify which bridge holds the deposit. Confirm whether it is the chain's canonical bridge or a third party. If third party, read the validator set size, the threshold, the key-storage model (hot, warm, cold, HSM, MPC), and whether validators are operated by independent entities on independent infrastructure. Check whether the quorum parameter is upgradeable and by whom. A bridge whose upgrade admin is a 2-of-3 multi-sig held by the same team that runs the validators is not meaningfully decentralized regardless of how the signature scheme is described in the docs.

The July 23 tape also included exploits at Verus and B² Network, bringing the six-hour bridge loss total to $35.55M. The common thread across all three was not the chain, the language, or the asset. It was the trust model in the bridge layer.

What Koinlytics tracks: We monitor bridge validator set composition, threshold parameters, key custody disclosures, and upgrade admin structures for every third-party bridge our covered protocols route through. When a protocol's stated security model diverges from its operational reality, we flag it before the outflow, not after.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics