← Radar

Incident case file

Sign in to watch

AFX Trade — Arbitrum USDC bridge validator key compromise

Incident date July 22, 2026

1 views

ActiveArbitrum → EthereumBridge / Private Key CompromiseCluster: AFX-KEYCOMP-2026-07

Estimated loss

$24.1M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Holding wallet (ETH): 0x627654B2782bfC57580ecD11d40869b350B6ebAC | Attacker Safe / Gnosis Multisig (Arbitrum + ETH): 0x2f2974fabc54dba33442261211c06bd20e0feefc | Operator-EOA (Arbitrum): 0x5553ea7bda594ade7afe91d279779a42b2b84208 | Gas-Funder (Arbitrum + ETH): 0x32e3200d6e944cd9bd1c8c9865293b07206e7a01 | Attribution: UNC4899 / TraderTraitor (North Korea, Lazarus subgroup) — attributed by zeroShadow and SEAL, confirmed by AFX

Funds moved to: 24,150,000 USDC drained from AFX bridge on Arbitrum (exploit tx: 0x50d0b3ec6c3f5fce0f10abf81540bbb508f421494aa2b3480c4a264b0436547b, 22 Jul 21:30 UTC) → split into 6 tranches (7.5M / 5M / 5M / 5.895M / 655K / 100K USDC) via BridgingKit → bridged Arbitrum→Ethereum via Circle CCTP v2 (burn 21:33–21:38 UTC, mint 21:33–21:38 UTC) → swapped for ~12,467.5 ETH via DEX aggregator → consolidated in holding wallet 0x627654B2782bfC57580ecD11d40869b350B6ebAC (22 Jul 21:42 UTC). As of July 25:
AFX Bridge contract (drained, Arbitrum): 0xcb3b9a3e5668afe84dc7a864b36b845dce062e67 | BridgingKit (Arbitrum): 0xb3fa262d0fb521cc93be83d87b322b8a23daf3f0 | TVL before exploit: ~$24.18M USDC | Audit: Zellic (pre-incident) | Pre-attack: Operator-EOA funded May 12, 2026 (~2 months before exploit); funding chain traces to 2024 with no CEX at early hops — consistent with professional pre-planned infrastructure. Arbitrum native bridge NOT affected (confirmed by Steven Goldfeder, Offchain Labs). Bridg

Timeline: On July 22, 2026 at 21:30 UTC, Blockaid detected an exploit targeting the AFX Trade perpetuals DEX bridge on Arbitrum. The attacker had pre-staged the Operator-EOA since May 12, 2026. At T0, they used 5-of-7 compromised hot-validator signatures to meet quorum and authorize a withdrawal of 24,150,000 USDC — virtually the entire bridge TVL of ~$24.18M. The funds cleared the ~200-second dispute window without contest. The USDC was aggregated by Attacker Safe (0x2f2974fa...feefc) and routed through BridgingKit (0xb3fa262d...af3f0) in 6 tranches across the Circle CCTP v2 bridge to Ethereum between 21:33–21:38 UTC. On Ethereum, the Safe swapped all USDC into ~12,467.5 ETH (~$1,937/ETH average) via a DEX aggregator between 21:34–21:41 UTC, then forwarded 12,467.437 ETH to the final holding wallet 0x627654B2782bfC57580ecD11d40869b350B6ebAC at 21:42 UTC. Offchain Labs co-founder Steven Goldfeder confirmed the Arbitrum native bridge was not involved. AFX suspended the bridge and on July 23 publicly offered the attacker a 70/30 white-hat split (return 70%, keep ~$7.2M bounty). Funds remained immobile for 3 days. On July 25, the attacker began laundering: ETH was fanned out into ~12 near-equal tranches (~100–600 ETH each) that converged on the THORChain Router (0xd37bbe57...), where streaming swaps converted ETH to native Bitcoin across 5 distinct BTC addresses. By July 25 noon, ~57% (~$14M) had been moved through THORChain to Bitcoin. zeroShadow and SEAL publicly attributed the attack to North Korean APT group UNC4899 / TraderTraitor; AFX confirmed this attribution.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)