#AFXBridgeHack24M

241,8 K vizionează|107 postare

About AFXBridgeHack24M

On July 22, Perp DEX AFX Trade's Arbitrum bridge was allegedly drained of 24.15M USDC, later bridged to Ethereum and swapped for 12,467 ETH. Two more attacks hit the same night: B2 Network on BNB Chain lost about 8.59M B2 tokens (around $3.86M), and algorithmic stablecoin Balance Coin crashed over 99% via an oracle price bug, netting the attacker about $912K. CertiK reported 52 wrench attacks in H1 2026, about $124M in losses, up roughly 11.8x YoY. Ostium resumes trading July 23 at 22:00.

Cripto asociate
ARB
-3,06 %
ETH
-0,32 %
USDC
+0,21 %

AFXBridgeHack24M Postări populare

TBNG_OKX
TBNG_OKX
#AFXBridgeHack24M Three DeFi Hacks in One Night: What July 22 Says About Where Security Still Falls Short July 22 was a rough one. Three separate protocols got hit in a single night, and the combined damage tells you something uncomfortable about where DeFi security still has gaps. The biggest: Perp DEX AFX Trade's Arbitrum bridge was drained of 24.15M USDC. The attacker bridged it to Ethereum and swapped into 12,467 ETH. Clean, fast, hard to reverse. Bridge exploits are nothing new, but $24M in USDC walking out the door in one transaction is a reminder that cross-chain infrastructure remains one of the most dangerous seams in the stack. Same night, B2 Network on BNB Chain lost around 8.59M B2 tokens (roughly $3.86M). Then a third hit: algorithmic stablecoin Balance Coin collapsed over 99% through an oracle price bug, netting the attacker about $912K. Oracle manipulation as an attack vector has been documented for years. It keeps working. Separately, Ostium has announced it's resuming trading July 23 at 22:00 UTC after its own recent pause. The macro context makes this harder to shrug off. CertiK's H1 2026 report logged 52 physical "wrench attacks" alone, about $124M in losses, up roughly 11.8x year-over-year. That's the off-chain threat. On-chain, the tooling for auditing bridges and oracle integrations clearly still isn't keeping pace with deployment speed. The question worth sitting with: at what point do repeated bridge and oracle exploits start meaningfully affecting where liquidity chooses to sit? Share your thoughts in the comments 👇
NEXORA_
NEXORA_
HOT TOPIC: Hackers hit $BTC and $ETH DeFi 💸 $24M drained from AFX. $7.5M from Verus, through the same bug as May. $3.9M from B². All within 6 hours. Every loss came down to stolen keys or logic flaws. Is any bridge actually safe?
Alpha TraderX
Alpha TraderX
LATEST: AFX Trade’s bridge on Arbitrum was exploited for $24.15M in $USDC , with the team offering a 30% white hat bounty for the return of funds.
Knox BTC
Knox BTC
WTF is happening in crypto? In just one day, hackers exploited 3 crypto projects, stealing $35.56 million. AFX Trade exploited for $24.15 million. Verus exploited for $7.55 million. B² Network exploited for $3.86 million. We are already down 80%-90%, and whatever is left is now being hacked. $BTC
Trading Insight_News
Trading Insight_News
$ARB Arbitrum's AFX Bridge Attacked, $24.15 MillionUSDCStolen The AFX protocol within theArbitrumecosystem has been attacked, specifically targeting the cross chain bridge it operates on, resulting in the theft of approximately $24.15 million USDC. 🔸 Blockaid is collaborating with theArbitrumteam to respond, communicating with affected protocols and assisting in freezing the stolen funds. 🔸 Steven Goldfeder, co-founder of Offchain Labs, confirmed that the transactions originated from a third party protocol and asserted that Arbitrum's original bridge had never been attacked. 👉 This is the third bridge attack in less than a week (following Allbridge and Wanchain), highlighting the growing popularity of cross chain protocols among hackers. The theft of $24 million USDC represents a significant loss and will impact user confidence inArbitrum's bridge solutions. Although Arbitrum's native bridge remains secure, this incident serves as a reminder of the risks involved in using third-party bridges. 💬 Are you using crosschain bridges onArbitrum? Does this incident raise concerns about the security of your assets? News is for reference, not investment advice. Please read carefully before making a decision.
Birdie_OKX
Birdie_OKX
Another week, another bridge. AFX, an Arbitrum-based protocol, was drained of roughly $24M in USDC after its bridge keys were compromised, one of over a dozen crypto security incidents this month. Note the pattern: the exploit hit an offchain component, not a smart-contract bug. That distinction is the whole lesson. The industry has gotten good at auditing contracts; the soft underbelly now is operational security, keys, bridges, the human and infrastructure layer around the code. Bridges remain crypto's most concentrated risk because they pool value and lean on trust assumptions users rarely see. Not a reason to write off DeFi, a reminder that "not your keys" applies to protocols too. Security is a process, not an audit badge. NFA. #AFXBridgeHack24M #OKXOrbit
Renee_OKX
Renee_OKX
#AFXBridgeHack24M #AFXBridgeHack24M AFX Trade, a decentralized perpetuals exchange on Arbitrum, lost $24.15M when an attacker compromised validator signing keys for its cross-chain bridge — five hot-validator signatures met the two-thirds quorum needed to authorize a fraudulent 24.15M USDC withdrawal. Blockaid detected it July 22 at 21:30 UTC; the attacker bridged funds to Ethereum and swapped them into 12,467 ETH, nearly emptying AFX's entire TVL. Arbitrum's own native bridge wasn't touched — Offchain Labs co-founder Steven Goldfeder confirmed it was a third-party protocol compromise, not an Arbitrum vulnerability. The pattern matches a broader 2026 trend: off-chain key/infrastructure compromises, not smart contract bugs, are behind most major hacks this year — echoing April's $285M Drift Protocol breach. The timing was brutal: a separate Verus Ethereum Bridge exploit ($7.5M, using a near-identical technique to a May breach) hit just hours later, bringing combined bridge losses to $31.6M in a single 7-hour window — making this the 14th crypto security incident in July, a month that's already exceeded June's total hack losses.
zeroShadow
zeroShadow
zeroShadow, in collaboration with @_SEAL_Org, have identified that the recent AFX Bridge Exploit is highly likely linked to UNC4899 (North Korean subgroup TraderTraitor). Through extensive on-chain analysis, a link has been identified between the gas funding of this exploit to that of the recent KelpDAO exploit. A number of data points were also identified, which are consistent with this threat actor and recent exploits. zeroShadow will continue supporting this research and sharing known illicit address information to help stop the movement of these funds.
CoinDesk
CoinDesk
UPDATE: Three crypto exploits in a single day, $35.55M in total losses. @AFX_XYZ: $24.15M @VerusCoin: $7.55M @BSquaredNetwork: $3.86M
MasterChief🩸
MasterChief🩸
AFX got drained of $24m this week and the way it happened should worry every protocol nobody broke the code, no smart contract exploit even no bug the attacker stole the signing keys to a bridge AFX operates and once you hold the keys, you don't hack, you just open it directly $24.15m in usdc bridged to eth and swapped into 12,467 eth, all sitting in one wallet everyone can see and nobody can touch team responded: a public offer: keep 30% as a "bounty" if you return the rest, that's $7.2m for the thief and this is the third key compromise attack this year following the same script - drift in april, verus in may and now AFX projects spend millions auditing every line of code then hand the keys to a few laptops and hope the next $24m won't be lost to bad code either
Lil Auntie 🌮
Lil Auntie 🌮
Happy Friday. $35.55M drained from three protocols in a 6 hour span. AFX, $24.15M: the attacker got the validator keys to a bridge AFX runs itself. The contract worked perfectly, but for the wrong person. AFX publicly offered to let the hacker keep 30% if they return the rest. So far the funds haven't moved. B², $3.86M: the attacker took over the staking contract's upgrade authority and dumped 8.59M tokens into thin liquidity. 10% bounty on the table. Investigator Specter notes the compromised admin role had been active for over a year, and says that may point to an insider. Verus, $7.54M: same bridge, same entry path as their $11.5M hack in May. Blockaid says likely a different attacker this time. In May, Verus settled by letting the hacker keep 25% and got the rest back. Then they redeposited the recovered funds into the same unpatched bridge on July 8. Two weeks later it was gone again, this time straight through Tornado Cash. Two bounty offers open. One bridge robbed twice through the same door. Defi - the future of finance. —————————————— Disclaimer: independent research (could be wrong). Always DYOR.
Lil Auntie 🌮
Lil Auntie 🌮
The June recap. been a relatively quiet and peaceful month. But the risk is in places most people never look. Some are crazy (check Silent Swap) The receipts: > $75.87M lost across 40 hacks in June (PeckShield) > Aztec: hit twice in 4 days, ~$4.3M, both products shut down years ago > Secret Network: $4.67M drained, nobody noticed for 7 days > Jared's MEV bot: baited and drained for $7.5M > Syscoin: ~$10M minted out of thin air, then RETURNED and burned (rare W) > Silent Swap: malware that swaps the wallet address you just pasted (insane) > Amazon Q: one file in a downloaded repo could hand over your cloud keys (patched) What do these have in common? Almost none of the money came from a live protocol getting outsmarted. Aztec's drained products were abandoned in 2022 and 2023. The team gave up the admin keys when they shut them down, which means no patch and no pause button. The code sat there unguarded, still holding user money. Secret Network got robbed on Jun 10 and found out a week later, when a withdrawal failed because the vault was already empty. Nobody was watching. Jared, the most notorious sandwich bot on Ethereum, wasn't hacked either. An attacker spent weeks planting fake tokens that looked like easy profit. The bot kept granting spending permissions to trade them. Then the attacker used those permissions to empty it. (see below video) And Silent Swap doesn't touch protocols at all. It hides in a fake 'Google Notes' browser extension and quietly replaces the wallet address in your clipboard. You copy the right address, you paste the attacker's. Why you should care: your habits check the loud stuff. The dapp, the token, the chart. These attacks live in the quiet stuff you stopped checking. - Old approvals. - Dead protocols you used once in 2022. - Browser extensions. - The paste itself (Silent Swap) What to actually do: 1. Revoke old token approvals, especially anything you haven't touched in a year. 2. If a protocol you used shut down, get your funds out. Deprecated does not mean safe. It means unguarded. 3. Verify every address you paste. First 6 and last 6 characters, every single time. 4. Audit your browser extensions. If you don't remember installing it, remove it. 5. If you code with AI assistants, keep them updated, and don't open strangers' repos with the agent switched on. Stay Safu.