HomeAll NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

AFX Protocol loses $24M in exploit; Arbitrum bridge unaffected

Created at 23 Jul · 1:56 AM1 source↑ Market-relevant
IN SHORT

AFX Protocol, a decentralized exchange on Arbitrum, reportedly lost $24.15 million in a bridge exploit. Security firms confirmed the incident targeted a third-party protocol, not Arbitrum's native bridge infrastructure. The attacker used a compromised oracle key to fabricate profits and withdraw funds.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$24.15 millionreported loss in AFX Protocol exploit
$18 million - $24 millionestimated USDC loss from Ostium's OLP vault
28%percentage of Ostium's OLP vault value siphoned
4%decline in ARB token price
200leverage offered by Ostium on perpetual contracts

Who's Involved

AFX Protocol
decentralized perpetual exchange on Arbitrum affected by exploit
Offchain Labs
confirmed Arbitrum's native bridge was not compromised
Stephen Goldfeder
Co-founder of Offchain Labs, confirmed third-party protocol involvement
Blockaid
security firm that detected the exploit
Ostium
decentralized exchange focused on real-world asset trading, victim of exploit
Kaledora
Ostium founder who confirmed breach timing
AFX Protocol loses $24M in exploit; Arbitrum bridge unaffected

↳ Why This Matters

This exploit highlights the risks associated with oracle infrastructure in DeFi protocols, even when the underlying blockchain network's bridge remains secure. It underscores the importance of robust key management and security practices for protocols relying on external data feeds, impacting investor confidence in oracle-dependent DeFi platforms.

Key facts

  • AFX Protocol reportedly lost $24.15 million in a bridge exploit on Arbitrum.
  • The exploit targeted a third-party protocol, not Arbitrum's native bridge infrastructure.
  • An attacker gained access to a compromised oracle signer private key within Ostium.
  • The attacker used falsified, future-dated price reports to fabricate trading profits.
  • Approximately $18 million to $24 million in USDC was withdrawn from Ostium's OLP vault.
  • The stolen funds were bridged to Ethereum and converted to ETH, with much sent to Tornado Cash.

AFX Protocol, a decentralized perpetual exchange operating on the Arbitrum network, reportedly suffered a loss of approximately $24.15 million due to an exploit targeting one of its cross-chain bridges. Security firm Blockaid detected the incident on July 15, 2026, around 9:30 p.m. UTC. The exploit involved a compromised oracle signer private key within the Ostium protocol, a decentralized exchange focused on real-world asset trading built on Arbitrum.

The attacker utilized the compromised key to authorize a future-dated, falsified price report. This allowed the attacker to create artificial trading profits on the Ostium platform, leading to the withdrawal of approximately $18 million to $24 million in USDC from Ostium's liquidity vault, known as the OLP. The stolen funds were then bridged to Ethereum, converted to ETH, and a significant portion was sent to Tornado Cash.

Offchain Labs, the developer of Arbitrum, confirmed that the incident affected a third-party protocol and did not impact Arbitrum's native bridge infrastructure. Stephen Goldfeder, co-founder of Offchain Labs, emphasized that the Arbitrum network's core infrastructure remained secure. Ostium founder Kaledora confirmed the breach occurred within a five-minute window and that the team had trading contracts paused within the hour.

In the aftermath, Ostium halted all trading operations and froze affected positions. The exploit, while significant for Ostium and its liquidity providers, is considered a contained problem rather than a systemic risk to the Arbitrum ecosystem. The ARB token experienced a decline of approximately 4% following the news, which analysts attributed to a knee-jerk reaction.

Frequently asked questions

AFX Protocol is a decentralized perpetual exchange that operates on the Arbitrum blockchain, allowing users to trade perpetual futures contracts.

No, security experts and Offchain Labs confirmed that the Arbitrum native bridge was not hacked. The exploit targeted a third-party protocol's bridge.

The attacker gained access to a compromised oracle signer private key for Ostium, a related protocol. This allowed them to submit falsified price data, create artificial profits, and withdraw funds.

Ostium is a decentralized exchange on Arbitrum specializing in perpetual trading of real-world assets like stocks, commodities, and forex.

What Happens Next

01Ostium is conducting a full investigation into the oracle key compromise.
02Investors are advised to scrutinize oracle management and signer key privileges in DeFi protocols.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

AFX Protocol reportedly lost $24.15 million in a cross-chain bridge exploit.
Blockaid detected the exploit targeting a bridge operated by AFX.
Offchain Labs confirmed the incident affected a third-party protocol, not Arbitrum's native bridge.
The attacker used a compromised oracle signer private key to falsify price reports.
The attacker fabricated trading profits and withdrew approximately $18 million to $24 million in USDC from Ostium's OLP vault.
The attacker moved most of the stolen USDC to Ethereum, swapping it for ETH and sending it to Tornado Cash.
Ostium halted trading operations and froze affected positions.
The ARB token saw a decline of approximately 4% following the news.
Sponsored

London Quick Take - 22 July - UK inflation softens, oil rises and chips rally ahead of Alphabet, Tesla earnings

SAXO

Sources

T1
AFX Protocol reportedly loses $24M in bridge exploitOffchain Labs said the incident involved a third-party protocol and did not affect Arbitrum’s native bridge infrastructure.Cointelegraph
T2
Ostium Hack 2026: What Happened in $24M Oracle Exploit?coingabbar.com
T2
Arbitrum bridge not hacked as $24M exploit drains Ostium DEX through ...cryptobriefing.com

Related Stories

Midnight token rebounds 19% after Wanchain bridge hack, Hoskinson calls for ZK revamp
22 Jul · 11:56 AM
SecondFi to wind down after $2.6M ADA theft linked to wallet flaw
22 Jul · 9:56 AM
Crypto institutions prioritize operational security over audits: Hacken
22 Jul · 12:16 PM
Zilliqa Ledger app vulnerability allows private key recovery
22 Jul · 12:06 PM
HTX Rebuilds Wallet Infrastructure After UK Sanctions, TRM Labs Reports
22 Jul · 12:51 PM