Loading prices…
STKR NewsSTKR News0 of 3 free this month
DeFi

Arbitrum Perp DEX AFX Trade Drained of $24M, Offers Hacker 30% to Return It

A $24 million drain on Arbitrum DEX AFX Trade highlights the persistent danger of custody bridges and the increasingly desperate trend of 30% bug bounties.

Originally on Decrypt
AB

Adrian Boysel

Contributor

Jul 23, 2026

4 min read

Photo illustration / STKR News

The Anatomy of a Bridge Drain

Another day, another nine-figure ecosystem took a body blow. This time it was AFX Trade, a perpetual decentralized exchange running on Arbitrum. Roughly $24 million in user assets vanished into the ether, and the post-mortem follows a script we have seen far too many times in the builder community. It was not a flaw in the Arbitrum L2 itself, but a failure in the proprietary plumbing connecting the app to the outside world.

Early reports indicate that the attacker bypassed security measures on the specific custody bridge operated by AFX. This is a critical distinction for founders to understand. When we talk about "Ethereum security" or "Arbitrum scaling," we often ignore the fact that the weakest link is almost always the custom bridge sitting in the middle. The stolen funds were quickly converted and bridged over to the Ethereum mainnet, a common move to obscure the trail before using mixers.

The Vulnerability of Custom Infrastructure

As builders, we are often tempted to roll our own infrastructure to save on fees or provide a smoother user experience. AFX Trade did exactly that. By operating their own custody bridge, they took on the responsibility of a bank without necessarily having the institutional safeguards of one. The exploit targeted the bridge mechanism directly, allowing the attacker to drain the liquidity pools that back the perpetual trading platform.

This should serve as a wake-up call for anyone building perp DEXs. These platforms are honey pots by design. They require deep liquidity to function, and if that liquidity is sitting behind a custom-coded bridge, you are essentially painting a target on your back. The complexity of managing cross-chain state is where most projects fail. It is rarely the smart contract logic of the trade itself that breaks; it is the movement of the money.

The 30% Negotiation Tactic

In a move that feels increasingly like a standard operating procedure for compromised DeFi projects, AFX Trade has publicly reached out to the exploiter. They offered a 30% white-hat bounty in exchange for the return of the remaining 70% of the funds. This is a massive jump from the traditional 10% bounty we saw in previous years.

  • Bounties are getting larger because projects are desperate to avoid total collapse.
  • A 30% cut on $24 million is roughly $7.2 million—a life-changing sum that suggests the team is willing to do anything to make users whole-ish.
  • This sets a dangerous precedent for the industry, potentially incentivizing "bold" developers to exploit their own systems for a clean exit under the guise of a bounty.

From a founder’s perspective, this negotiation is a sign of extreme weakness. It tells the market that the team has no other way to recover the funds and likely no insurance or treasury backstop to cover the loss. It is a Hail Mary pass in a game they are already losing.

Why Builders Should Care

If you are building in the Arbitrum ecosystem, or any L2 for that matter, you need to audit your dependencies. We often focus on our own code while ignoring the "immutable" bridges we rely on. If a project in your ecosystem goes down for $24 million, it affects the total value locked (TVL) and the general trust in the network. Even though Arbitrum's core technology was not at fault, the headline still reads as a failure of the ecosystem.

We have to stop treating bridges as an afterthought. If your project requires a bridge, use the canonical ones provided by the L2 foundation whenever possible. They might be slower, and they might have fewer features, but they have been battle-tested by thousands of users and millions in volume. Speed-running your own bridge to gain a competitive edge in the perp market is a recipe for a $24 million disaster.

Risk Management Over Hype

The culture of "move fast and break things" works for social media apps. It does not work for financial protocols handling tens of millions of dollars. The AFX Trade exploit is a reminder that the cost of moving too fast is often permanent. Once those funds hit the Ethereum mainnet and get washed through a privacy protocol, they are gone. No amount of social media pleading will bring them back if the hacker doesn't feel like being generous.

We need to move toward a builder culture that prioritizes formal verification and multi-signature bridge controls over quick-launch features. If you cannot afford to have your bridge audited by two or three independent firms, you probably shouldn't be running a bridge. Use an existing provider or wait until you have the capital to do it right.

Looking Ahead

The fallout from the AFX Trade drain will likely lead to more scrutiny on Arbitrum-based perp protocols. We should expect to see a flight to quality, where users move their capital to established players like GMX or dYdX who have survived multiple cycles. For the smaller teams, the message is clear: your security is your product. If you lose the money, the UI/UX and the low fees don't matter at all.

For those of us watching from the sidelines, this is a moment to re-evaluate our own portfolios and the projects we support. Are the yields high because the protocol is innovative, or are they high because the team is cutting corners on security infrastructure? More often than not, it is the latter.

The most expensive code in crypto is the code that was written to save time.

As of now, the hacker has not responded to the 30% offer. The crypto community is watching the wallet addresses, but the reality is that the damage is done. Whether the funds are returned or not, the reputation of AFX Trade is likely irrecoverable. Builders, take note: you get one chance to protect your users' capital. Don't waste it on a shortcut.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses