AFX cross-chain bridge hacked: 24.15 million USDC stolen

CN
14 hours ago

On July 23, 2026, at 5:30 AM Beijing Time, the cross-chain bridge operated by the AFX protocol on the Arbitrum ecosystem was breached. According to a single public source, approximately 24.15 million USDC was transferred out in a short period and is considered stolen. This security attack on the cross-chain bridge quickly resonated throughout the Arbitrum and broader DeFi community, highlighting the inherent risks of cross-chain infrastructure that “centralizes custody of large multi-chain assets yet is frequently subjected to attacks.” Shortly after the attack occurred, the security monitoring agency Blockaid detected anomalies and announced that it had collaborated with the Arbitrum team and the affected protocol to attempt to freeze the stolen funds on-chain and control further losses. However, as of now, authoritative explanations regarding specific attack methods, the identity of the attacker, and the actual amount of funds successfully frozen or recovered have not been provided through public channels, adding new uncertainties for subsequent risk assessments and governance plan formulations.

Cross-Chain Bridge Breached: 24.15 Million USDC Transferred Away

As the asset custody and cross-chain channel within the AFX system, this cross-chain bridge was almost directly hit following the attack: statistical data from a single public source indicated that around 24.15 million USDC was transferred out from the custody end in a very short time, turning the cross-chain bridge from a “liquidity hub” into a funding gap. For users relying on this channel to move assets between different networks, this is not an abstract number but a direct concern related to custody security and the sudden failure of a core infrastructure for cross-chain experience.

At the protocol level, the scale of this loss is sufficient to be categorized as a serious security incident. Its impact first falls on the existing users of AFX and its cross-chain bridge, and further may spread to questions regarding the overall security of the Arbitrum ecosystem. The cross-chain bridge has long played the role of a centralized custody point for multi-chain assets in DeFi, with the downside of its convenience being a “single failure could lead to significant losses.” The event occurring within the Arbitrum ecosystem has once again presented this hidden danger in real numbers to the participants.

Blockaid Sounds the Alarm

As the attack unfolded on-chain, the security monitoring agency Blockaid's system was the first to capture abnormal fund flows, triggering an alarm. As a common "frontline sentinel" in multiple security incidents, Blockaid quickly intervened after identifying the unusual behavior of addresses related to the AFX cross-chain bridge, shifting from technical monitoring to coordinated response, transforming from merely “identifying issues” to prompting all parties into emergency response mode.

Subsequently, Blockaid released a statement indicating that it was in communication with the Arbitrum team and the affected protocol, assisting in emergency management. The core of the current work is attempting to freeze part of the stolen assets on-chain to hinder the attackers from further transferring and splitting funds. According to public information, the specific amounts that have been frozen or successfully recovered have not been disclosed, indicating that the actual effectiveness of this pre-warning and coordinated freezing still needs to be verified. However, it can be confirmed that Blockaid has once again acted as a monitoring and coordination hub in a blockchain security incident, having a certain but unquantified impact on reducing the scale of losses.

The High-Risk Target Behind Cross-Chain Bridges

Prior to the breach of the AFX cross-chain bridge, cross-chain bridges were already considered one of the most “cost-effective” infrastructures in the eyes of hackers. They connect multiple chains simultaneously, allowing users to transfer assets between different networks, but often concentrate large amounts of funds at one end in the form of contracts or relay mechanisms. Once there is a flaw in the verification logic or permission control, an attacker only needs to tear open a gap to directly access the multi-chain asset pool, this concentrated risk structure inherently pushes cross-chain bridges into a high-risk target position.

More critically, the complexity of cross-chain bridges in the verification and cross-chain messaging segments increases the risk. Compared to single-chain applications, cross-chain bridges must reach “trusted synchronization” for state changes across different consensus systems, involving multiple steps such as signing, multi-party verification, message ordering, timeouts, and rollbacks. Any poorly designed interface, ambiguous audit boundaries, or lack of exception handling can evolve into exploitable attack surfaces. Research and industry observations have long listed cross-chain bridges as one of the most frequently attacked infrastructures in DeFi. Historical cases of large-scale theft have occurred on cross-chain bridges or related bridging protocols. The AFX cross-chain bridge being breached on the morning of July 23, 2026, simply continues this risk narrative, reaffirming that security issues in the cross-chain field have yet to be fundamentally alleviated; under the existing technical and governance framework, cross-chain bridges remain one of the infrastructures in the entire DeFi landscape that require heightened vigilance.

A Glimpse Into the Security Linkage of the Arbitrum Ecosystem

Within hours of the AFX cross-chain bridge breach, the security monitoring agency Blockaid publicly declared it was collaborating with the Arbitrum team and the affected protocol to respond and attempted to push for the freezing of stolen funds on-chain. This itself is a signal: on the mainstream Ethereum Layer 2, which gathers numerous DeFi protocols and cross-chain bridges, a certain degree of linkage framework has already formed among security agencies, protocol parties, and ecosystem operators. The true factor determining whether losses can be contained is not just the technical means themselves but the communication efficiency and decision-making speed from detecting anomalies to transmitting information and executing responsive actions on-chain.

From the perspective of the entire Arbitrum ecosystem, this AFX incident can also be viewed as an unyielding stress test. Public information reveals that currently, neither Arbitrum nor AFX has officially disclosed complete technical details or follow-up plans. However, it can be confirmed that the ecosystem has entered an emergency response state. Based on past experiences, similar security incidents often force public chain ecosystems to streamline emergency processes, upgrade audit requirements and risk alerts. Arbitrum's performance in this regard will directly influence the prioritization of subsequent investments in security infrastructure and whether high-risk infrastructures like cross-chain bridges will be incorporated into stricter, executable ecosystem security norms.

What Can We Do Before the Next Bridge is Breached

In the absence of public disclosure of technical details, compensation arrangements, and complete follow-up plans, the AFX event has already sufficiently revealed the weak points in the security boundary of cross-chain bridges, and placed the issue of “who will participate and how to engage in third-party security collaboration” on the table. The coordination in response by Blockaid and the Arbitrum team this time provides a relatively clear model for ecosystem-level security collaboration: how to coordinate when incidents arise, which roles must be involved, and how to promote attempts to freeze on-chain. For other cross-chain bridges, the more realistic question is whether these mechanisms can be written into the rules before incidents occur rather than being pieced together afterward. For users and protocol parties, there is also a need to adjust perspectives — cross-chain is not just about “how fast from A to B,” but about which addresses funds will pass through, who will custody them, and whether there are predictable interception and loss mitigation options when anomalies occur. Past incidents have repeatedly reminded the industry that cross-chain bridge security lacks unified standards. The loss of approximately 24.15 million USDC will be long cited as a cautionary tale, pushing ecosystems like Arbitrum to discuss the bottom line of bridging security, rigid requirements for audits, and how security entities like Blockaid can be systematically incorporated into emergency collaboration, which may be the only path to genuinely reducing harm before the next bridge is compromised.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink