Another week, another multi-million-dollar hack in DeFi, and once again, it’s an off-chain compromise rather than a smart contract exploit.
AFX Trade, a decentralized perpetuals exchange that settles in dollar-pegged stablecoin USDC, was drained of about $24.15 million on Wednesday after an attacker compromised the validator signing keys behind a bridge the protocol operates on Arbitrum, blockchain data shows.
In other words, the smart contract did what it’s supposed to do – verify the signature and execute the transaction. The problem was with the private keys that generated those signatures, as attackers compromised the private validator signing keys (hot keys held offchain by the bridge operators or validators).
Steven Goldfeder, co-founder of Offchain Labs, which develops and maintains the network, said the Arbitrum native bridge “has not been hacked or exploited in any way” and that the transaction originated from a third-party protocol.
A hack of Arbitrum’s own bridge would signal risk across the entire layer-2 network, but a compromised protocol running on top of it is a contained failure.
Nothing in the bridge’s own code logic was broken. Bridges are blockchain-based tools for transferring tokens between various networks, including those they were not initially supported on.
