Go to app

Incident Summary

Published 7/23/2026, 1:41:05 AM

On July 23, 2026, the AFX Protocol (formerly Aviator) suffered a $24.15 million USDC exploit targeting its SkyBridge infrastructure on the Arbitrum One network [Source: https://www.kucoin.com/news/flash/arbitrum-ecosystem-protocol-afx-cross-chain-bridge-hacked-24-15m-usdc-stolen]. The attack was isolated to the third-party SkyBridge protocol and did not affect the Arbitrum native bridge [Source: https://phemex.com/news/article/arbitrum-protocol-afx-suffers-2415-million-usdc-theft-in-crosschain-bridge-attack-94255].

Incident Summary

MetricDetails
Total Loss$24.15 Million USDC
Asset ConversionSwapped for 12,467.5 ETH
Target ComponentSkyBridge (Third-party bridge powered by AFX)
Attacker Address0x6276ebAC...
NetworkArbitrum One

Root Cause and Technical Mechanism

The exploit stemmed from a vulnerability in the SkyBridge validation logic, which allowed the attacker to bypass security checks and drain the USDC liquidity pool [Source: https://phemex.com/news/article/arbitrum-protocol-afx-suffers-2415-million-usdc-theft-in-crosschain-bridge-attack-94255].

Key technical observations include:

Timeline of Events (July 22–23, 2026)

  • July 22, 21:30 UTC: Security monitor Blockaid detects the exploit in progress.
  • July 23, 05:30 AM (Beijing Time): The exploit is fully executed against the AFX SkyBridge.
  • July 23, ~06:00 AM: Security firms and the Arbitrum team begin investigating the drain.
  • July 23, ~07:00 AM: On-chain data confirms the conversion of USDC to ETH and the identification of the attacker's primary wallet [Source: https://x.com/ValeriusLabs/status/2080098103277895703].

While the immediate cause was a validation failure in the SkyBridge protocol, a full technical post-mortem detailing the specific code-level flaw (e.g., signature malleability or logic error) has not yet been released by the AFX team. Users are advised to exercise extreme caution as the protocol's security remains unverified following the incident.