Sorting by

×
  • Home
  • Crypto
  • AFX Trade hacker bounty stands at 30% for $24M return

AFX Trade hacker bounty stands at 30% for $24M return

Image

AFX Trade offers hacker 30% bounty after $24M bridge exploit

AFX Trade said it is offering the attacker behind a July 22 bridge exploit a 30% bounty if the remaining funds are returned, after roughly $24.15 million in USDC was drained from the protocol’s Arbitrum-connected bridge.[2][6] The offer puts a number on the recovery effort and underscores how quickly DeFi teams are turning to negotiated returns when stolen assets are already moved on-chain.[2][6]

Key Metrics

  • AFX Trade lost about $24.15 million in USDC in a bridge exploit, giving the incident immediate significance in July’s DeFi hack tally.[2][6]
  • The team offered the attacker 30% of the stolen amount, or roughly $7.2 million, in exchange for returning the rest.[2][6]
  • Reporting indicates the stolen USDC was bridged to Ethereum and swapped into about 12,467 ETH, reducing the likelihood of a clean freeze without cooperation.[2][8]
  • Offchain Labs said Arbitrum’s native bridge was not hacked, narrowing the issue to AFX’s own bridge stack and limiting contagion concerns.[2][3]
  • The incident was described as a bridge-key compromise, highlighting that custody and signing controls remain a live operational risk for DeFi protocols.[2][5]
  • AFX has suspended bridge operations while it assesses the damage and recovery options, leaving users exposed to timing risk until a verified plan emerges.[5][8]

Subscribe to our Social Media for Exclusive Crypto News and Insights 24/7!

AFX Trade’s 30% bounty follows a now-familiar crypto incident playbook: offer the attacker a legal off-ramp in exchange for most of the funds. The logic is straightforward. Once stolen assets are split, bridged and swapped, recovery becomes harder, and the value proposition shifts toward negotiated return rather than protracted enforcement efforts.[2][6]

AFX Trade hacker bounty centers on fund recoveryCopy

The core facts are consistent across the available reporting. AFX Trade was hit by a bridge exploit on July 22 that drained roughly $24.15 million in USDC, and the protocol then publicly asked the attacker to keep 30% if the remaining 70% was returned.[2][6][8] AFX’s offer was communicated after the exploit and was framed as a white-hat-style settlement.[2][4]

The reported size of the bounty matters because it shows how protocols are pricing recovery under stress. At around $7.2 million, the incentive is large enough to attract attention, but the structure also signals that AFX appears to be prioritizing partial restitution over a full legal standoff.[2][6] Market participants view that as a pragmatic response when the alternative is often zero recovery.[6]

What happened to the stolen fundsCopy

AFX Trade hacker bounty stands at 30% for $24M return

Security reporting says the attack was tied to compromised validator signing keys for AFX’s bridge layer, not Arbitrum’s underlying network.[2][3][5] One report said the attacker moved the USDC from Arbitrum to Ethereum and converted it into roughly 12,467 ETH at an average price near $1,937.[2] That kind of movement makes recovery more difficult because the assets are no longer sitting in a single frozen wallet.[2][6][8]

ItemVerified dataDirect implication
Estimated loss$24.15 millionLarge enough to stress confidence in bridge security
Bounty offered30%AFX is incentivizing voluntary return
Approximate recovery ask70% of fundsProtocol is seeking partial restitution, not full seizure
Reported post-exploit swap~12,467 ETHFunds were rapidly transformed, complicating tracing
Network impactArbitrum native bridge not hackedIncident appears isolated to AFX’s own bridge setup

Why the AFX Trade hacker bounty mattersCopy

The AFX Trade hacker bounty is important beyond the dollar amount because it speaks to investor behavior in a sector where bridge risk still weighs heavily on capital allocation. A public recovery offer can shorten the time between exploit and partial restitution, but it also reinforces the view that bridge infrastructure remains a weak point even when the base chain is unaffected.[2][3][5]

That distinction matters for competitive positioning inside DeFi. Offchain Labs’ confirmation that Arbitrum’s native bridge was not breached narrows the blame to AFX’s operational layer, which may limit spillover to the broader network.[3] But for users and liquidity providers, the practical takeaway is less nuanced: if a protocol controls its own bridge and signing keys, those controls become part of the investment case.[2][5]

The downside scenario is clear. If the attacker declines the offer, or if the funds have already been sufficiently laundered or dispersed, AFX may face a prolonged recovery process with little chance of full reimbursement.[6][8] Another uncertainty is whether the public bounty itself improves outcomes or simply sets a higher expected payout for future attackers, a concern raised in market commentary around the incident.[6]

AFX has not, in the reporting available here, confirmed a full recovery or a final settlement. Until that changes, the AFX Trade hacker bounty remains a live test of whether negotiated returns can still work in a market where stolen crypto can move across chains in minutes.[2][5][8]

  1. https://www.kucoin.com/news/flash/afx-trade-loses-24m-in-bridge-exploit-offers-hacker-30-bounty
  2. https://protos.com/defi-loses-35m-in-a-day-are-bounties-inviting-more-hacks/
  3. https://www.htx.com/fr-fr/feed/community/21162545/?comment=1
  4. https://www.bitget.com/amp/news/detail/12560605535501
  5. https://cryptodaily.co.uk/2026/07/afx-trade-hack-compromised-bridge-keys-24m
  6. https://coincodex.com/article/88131/afx-trade-tells-hacker-to-keep-30-of-the-24m-stolen-to-give-the-rest-back/
  7. https://coingape.com/afx-trade-bridge-drained-of-24-15m-usdc-on-arbitrum-attacker-swaps-for-12467-eth/

Read Disclaimer
This content is aimed at sharing knowledge, it's not a direct proposal to transact, nor a prompt to engage in offers. Lolacoin.org doesn't provide expert advice regarding finance, tax, or legal matters. Caveat emptor applies when you utilize any products, services, or materials described in this post. In every interpretation of the law, either directly or by virtue of any negligence, neither our team nor the poster bears responsibility for any detriment or loss resulting. Dive into the details on Critical Disclaimers and Risk Disclosures.

Share it

Source

AFX Trade hacker bounty stands at 30% for $24M return