An attacker drained approximately 24.15 million USDC from a bridge operated by AFX Trade, a protocol running on Arbitrum, at 21:30 UTC on July 22. Security firm Blockaid flagged the incident in real time and began coordinating with the Arbitrum team shortly after detection.

The stolen USDC was moved from Arbitrum to Ethereum and swapped into 12,467.5 ETH, according to blockchain security firm PeckShield. The converted funds were traced to a single wallet, 0x6276...ebAC. PeckShield noted the tally could still shift as the flow continues to be tracked.

Arbitrum Core Infrastructure Not Affected

As per Offchain Labs co-founder Steven Goldfeder, the native Arbitrum bridge was untouched. 'We're aware of a report of a bridge hack on Arbitrum and are investigating. We can confirm that the transaction in question originated from a third party protocol, and the Arbitrum native bridge has not been hacked or exploited in any way,' he stated.

The exploit targeted AFX's own bridge layer, a pattern seen repeatedly in cross-chain attacks this year, where third-party bridge infrastructure becomes the entry point rather than the underlying network.

DefiLlama data counted 13 hacks across crypto protocols in July before this incident, totalling $72.6 million in losses. The AFX breach brings that count to 14 events and pushes the monthly total to roughly $97 million, already above June's $75.32 million in hack losses. July is shaping up as one of the more damaging months of 2026 for the sector.

Whether AFX can freeze or recover any portion of the drained funds depends on how quickly on-chain trackers and exchanges can coordinate to flag the attacker's wallet.

This article is for informational purposes only and does not constitute financial or investment advice.