Arbitrum-Based Platform Loses $24M After Bridge Key Compromise
AFX Trade, an Arbitrum-based platform, was drained of $24.15 million in USDC after an attacker exploited compromised bridge keys tied to the external bridge operated by the project.
The attack used hot-validator signatures to authorize a massive withdrawal, circumventing standard safety thresholds that would normally require multiple independent approvals for such a transaction.
Validator signature vulnerabilities are a common issue with external bridges, which often rely on a smaller validator set and can be more susceptible to key compromise attacks.
The funds were withdrawn in a single transaction, and security researchers have noted that the attack vector points to poor key management practices rather than a smart contract flaw.