Another week, another multi-million dollar DeFi hack and once again, it’s an off-chain compromise rather than a smart contract exploit.
AFX Trade, a decentralized perpetual exchange that settles in the dollar-pegged USDC stablecoin, lost around $24.15 million on Wednesday after an attacker compromised validator signing keys behind a bridge the protocol operates on Arbitrum, blockchain data shows.
In other words, the smart contract did what it is supposed to do: verify the signature and execute the transaction. The problem was with the private keys that generated those signatures, as the attackers compromised the validator’s signing private keys (hot keys held off-chain by the bridge operators or validators).
Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said that Arbitrum’s native bridge “has not been hacked or exploited in any way” and that the transaction originated from a third-party protocol.
A hack of Arbitrum’s own bridge would signal a risk to the entire Layer 2 network, but a compromised protocol running on top of it is a contained flaw.
Nothing was broken in the bridge code logic. Bridges are blockchain-based tools for transferring tokens between various networks, including those where they were not initially supported.




