Incident case file
Sign in to watchAFX Trade — Arbitrum USDC bridge validator key compromise
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Holding wallet (ETH): 0x627654B2782bfC57580ecD11d40869b350B6ebAC | Attacker Safe / Gnosis Multisig (Arbitrum + ETH): 0x2f2974fabc54dba33442261211c06bd20e0feefc | Operator-EOA (Arbitrum): 0x5553ea7bda594ade7afe91d279779a42b2b84208 | Gas-Funder (Arbitrum + ETH): 0x32e3200d6e944cd9bd1c8c9865293b07206e7a01 | Attribution: UNC4899 / TraderTraitor (North Korea, Lazarus subgroup) — attributed by zeroShadow and SEAL, confirmed by AFX
Timeline: On July 22, 2026 at 21:30 UTC, Blockaid detected an exploit targeting the AFX Trade perpetuals DEX bridge on Arbitrum. The attacker had pre-staged the Operator-EOA since May 12, 2026. At T0, they used 5-of-7 compromised hot-validator signatures to meet quorum and authorize a withdrawal of 24,150,000 USDC — virtually the entire bridge TVL of ~$24.18M. The funds cleared the ~200-second dispute window without contest. The USDC was aggregated by Attacker Safe (0x2f2974fa...feefc) and routed through BridgingKit (0xb3fa262d...af3f0) in 6 tranches across the Circle CCTP v2 bridge to Ethereum between 21:33–21:38 UTC. On Ethereum, the Safe swapped all USDC into ~12,467.5 ETH (~$1,937/ETH average) via a DEX aggregator between 21:34–21:41 UTC, then forwarded 12,467.437 ETH to the final holding wallet 0x627654B2782bfC57580ecD11d40869b350B6ebAC at 21:42 UTC. Offchain Labs co-founder Steven Goldfeder confirmed the Arbitrum native bridge was not involved. AFX suspended the bridge and on July 23 publicly offered the attacker a 70/30 white-hat split (return 70%, keep ~$7.2M bounty). Funds remained immobile for 3 days. On July 25, the attacker began laundering: ETH was fanned out into ~12 near-equal tranches (~100–600 ETH each) that converged on the THORChain Router (0xd37bbe57...), where streaming swaps converted ETH to native Bitcoin across 5 distinct BTC addresses. By July 25 noon, ~57% (~$14M) had been moved through THORChain to Bitcoin. zeroShadow and SEAL publicly attributed the attack to North Korean APT group UNC4899 / TraderTraitor; AFX confirmed this attribution.
Sources and coverage
- Articlecoindesk.comhttps://www.coindesk.com/tech/2026/07/23/arbitrum-based-afx-trade-drained-of-usd24-million-after-bridge-keys-compromised
- Articletheblock.cohttps://www.theblock.co/post/409482
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articledefillama.comhttps://defillama.com/hacks
- Articlenftplazas.comhttps://nftplazas.com/afx-trade-bridge-exploit-drains-24-15m-usdc-on-arbitrum/
- Articlecryptodaily.co.ukhttps://cryptodaily.co.uk/2026/07/afx-trade-hack-compromised-bridge-keys-24m
- Articletracehex.dehttps://tracehex.de/t/FIKKwgWrnu
- Articleetherscan.iohttps://etherscan.io/address/0x627654B2782bfC57580ecD11d40869b350B6ebAC
- Articlearbiscan.iohttps://arbiscan.io/address/0xcb3b9a3e5668afe84dc7a864b36b845dce062e67
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)