Incident Summary
Published 7/23/2026, 1:41:05 AM
On July 23, 2026, the AFX Protocol (formerly Aviator) suffered a $24.15 million USDC exploit targeting its SkyBridge infrastructure on the Arbitrum One network [Source: https://www.kucoin.com/news/flash/arbitrum-ecosystem-protocol-afx-cross-chain-bridge-hacked-24-15m-usdc-stolen]. The attack was isolated to the third-party SkyBridge protocol and did not affect the Arbitrum native bridge [Source: https://phemex.com/news/article/arbitrum-protocol-afx-suffers-2415-million-usdc-theft-in-crosschain-bridge-attack-94255].
Incident Summary
| Metric | Details |
|---|---|
| Total Loss | $24.15 Million USDC |
| Asset Conversion | Swapped for 12,467.5 ETH |
| Target Component | SkyBridge (Third-party bridge powered by AFX) |
| Attacker Address | 0x6276ebAC... |
| Network | Arbitrum One |
Root Cause and Technical Mechanism
The exploit stemmed from a vulnerability in the SkyBridge validation logic, which allowed the attacker to bypass security checks and drain the USDC liquidity pool [Source: https://phemex.com/news/article/arbitrum-protocol-afx-suffers-2415-million-usdc-theft-in-crosschain-bridge-attack-94255].
Key technical observations include:
- Third-Party Vulnerability: Steven Goldfeder of Offchain Labs confirmed that the Arbitrum native bridge remained secure and that the flaw resided entirely within the AFX-operated SkyBridge [Source: https://www.kucoin.com/news/flash/arbitrum-ecosystem-protocol-afx-cross-chain-bridge-hacked-24-15m-usdc-stolen].
- Liquidity Drain: The attacker successfully manipulated the bridge's cross-chain messaging or validation to authorize the withdrawal of 24.15 million USDC.
- Transparent Exit: Following the drain, the attacker immediately swapped the USDC for ETH. Security analysts noted the "sloppy" nature of the exit, as the stolen funds (approximately 12,467.5 ETH) were consolidated into a single, unmixed wallet address:
0x6276ebAC[Source: https://x.com/ValeriusLabs/status/2080098103277895703].
Timeline of Events (July 22–23, 2026)
- July 22, 21:30 UTC: Security monitor Blockaid detects the exploit in progress.
- July 23, 05:30 AM (Beijing Time): The exploit is fully executed against the AFX SkyBridge.
- July 23, ~06:00 AM: Security firms and the Arbitrum team begin investigating the drain.
- July 23, ~07:00 AM: On-chain data confirms the conversion of USDC to ETH and the identification of the attacker's primary wallet [Source: https://x.com/ValeriusLabs/status/2080098103277895703].
While the immediate cause was a validation failure in the SkyBridge protocol, a full technical post-mortem detailing the specific code-level flaw (e.g., signature malleability or logic error) has not yet been released by the AFX team. Users are advised to exercise extreme caution as the protocol's security remains unverified following the incident.