A $24.15 million exploit on a third-party bridge operating on Arbitrum has turned into a very public lesson about which bridges you should trust with your crypto. Steven Goldfeder, CEO and co-founder of Offchain Labs, used the incident to outline exactly how his team thinks about bridge risk management, and why the native Arbitrum bridge sits in a fundamentally different security category.
The breach hit AFX Trade on July 22, when attackers compromised validator keys on the bridge protocol and drained approximately $24.15 million in USDC. The stolen funds were subsequently swapped for roughly 12,467 ETH. Goldfeder confirmed the exploit originated entirely from a third-party protocol and that Arbitrum’s native bridge remained secure throughout the incident.
Native vs. third-party: a distinction that matters
Arbitrum’s native bridge inherits its security directly from the rollup’s architecture, secured by the same mechanism that protects the entire Arbitrum network, which ultimately relies on Ethereum’s own security guarantees. Third-party bridges like AFX Trade operate independently, introducing their own trust assumptions, key management practices, and validator sets.
Goldfeder, who holds a Ph.D. in applied cryptography from Princeton University, emphasized that Offchain Labs has improved bridge security through a combination of technical measures and user education. The company also conducts due diligence on third-party bridges that operate within the Arbitrum ecosystem, though the AFX Trade incident demonstrates the limits of oversight when external protocols manage their own security infrastructure.







