New York
Est. 2024
Payney.
Finance · Markets · Decoded Daily
HomeCryptoAFX Arbitrum DEX Hacked $24M Custody Bridge Exploit
Crypto

AFX Arbitrum DEX Hacked $24M Custody Bridge Exploit

AFX perpetual DEX on Arbitrum lost $24M to custody bridge exploit. Platform offers hacker 30% bounty for return in major crypto security incident.

P
The Payney Desk
July 23, 2026 · 2 min read · Source: Decrypt
a close up of a bunch of gold coins
Photo by Traxer / Unsplash
a close up of a bunch of gold coins
The 30-second version Payney AI
  1. 01AFX, an Arbitrum perpetual DEX, lost $24 million through a custody bridge exploit, according to Decrypt.
  2. 02The stolen funds were moved to Ethereum, triggering an immediate bounty offer of 30% for their return.
  3. 03This incident exposes infrastructure risks in decentralized finance platforms and may pressure valuations of similar protocols.
  4. 04The outcome depends on whether the hacker negotiates the bounty or cashes out before exchanges flag the stolen crypto.

Arbitrum Perpetual DEX AFX Hit With $24M Custody Bridge Heist

AFX, a perpetual derivatives exchange built on the Arbitrum blockchain, has become the latest victim of a major cryptocurrency exploit. According to Decrypt, the platform lost $24 million through a vulnerability in its custody bridge—the mechanism that moves assets between blockchains. That's not pocket change, and it's the kind of incident that shakes confidence in supposedly secure infrastructure.

What makes this worse is where the money went. The stolen funds were transferred to Ethereum, creating a trail and a window of opportunity. In response, AFX's team did what's become standard playbook for hacked platforms: they offered the attacker a 30% bounty to return the assets. That's roughly $7.2 million in exchange for getting $24 million back.

So why does this matter to anyone outside the Arbitrum ecosystem?

Bridge exploits have become a recurring nightmare in DeFi. These cross-chain connectors are critical infrastructure, but they're also juicy targets because they concentrate large amounts of liquidity. And they're notoriously hard to secure. When one bridge fails, it erodes trust across the entire category—investors start asking whether their preferred bridge is next.

For holders of Arbitrum-native tokens or users with deposits on AFX, this is immediately painful. For the broader perpetual DEX market—where platforms like dYdX, Hyperliquid, and others compete fiercely—this is a credibility test. Frankly, this should have been caught sooner.

The real question is whether the hacker takes the deal.

A 30% bounty is substantial enough that it's worth considering for someone who wants to avoid being hunted by blockchain forensics firms or law enforcement. But it's also a negotiating opening. Some hackers push back, demanding higher percentages or additional privacy guarantees. Others simply dump the crypto on decentralized exchanges where traceability becomes much harder.

According to Decrypt's reporting, the funds are still on Ethereum—they haven't been laundered yet. That's the critical window. If AFX can convince the attacker that 30% in the hand beats the risk of getting caught with $24 million in stolen assets, there's a real path to recovery.

But there's also a darker possibility: the hacker walks away with the full amount, and AFX absorbs the loss.

For investors evaluating exposure to decentralized derivatives platforms, this incident raises a straightforward question: How are custody bridges audited on your platform of choice? Is there insurance? What's the protocol if something breaks? Most platforms don't have satisfying answers.

AFX itself hasn't made a public statement about whether this represents a flaw in their smart contract code or a broader issue with how the Arbitrum bridge architecture handles large transactions. That clarity will matter for whether this stays contained to AFX or signals a systemic problem.

The $24 million hack is already in the news. What happens in the next 48 to 72 hours—whether the hacker negotiates, dumps the assets, or disappears—will decide whether this becomes a footnote or a catalyst for larger market movements in the perpetual derivatives space.

Watch Ethereum's chain data closely. The stolen funds are visible to anyone tracking them. If they move to a mixer or exchange, recovery odds drop sharply.

Frequently asked
What is a custody bridge exploit and how did it drain AFX?
A custody bridge is a mechanism that moves crypto assets between blockchains. According to Decrypt, AFX's bridge had a vulnerability that allowed an attacker to steal $24 million and move the funds to Ethereum. The specifics of the code flaw haven't been fully disclosed.
Why is AFX offering 30% to get the money back instead of just 10%?
A 30% bounty ($7.2 million) is attractive enough to incentivize the hacker to negotiate rather than attempt to cash out or launder the full amount, which carries legal and technical risks. It's a cost-benefit calculation AFX is making to recover as much as possible.
Does this affect other Arbitrum DeFi platforms or just AFX?
This incident specifically hit AFX's custody bridge, but it raises questions about bridge security across Arbitrum. Other platforms should review their own cross-chain infrastructure, though this particular exploit doesn't automatically compromise unrelated projects.