The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

$42 Million in Eight Days: Why ‘Decentralised’ Stopped Protecting Perp DEX Traders

Ostium and AFX were drained inside eight days – both times through keys, not smart contracts. The seven questions you must answer before any deposit.

Featured image of $42 Million in Eight Days: Why ‘Decentralised’ Stopped Protecting Perp DEX Traders
7 min read
Share:
Categories: DeFiDEX

Within eight days in July, two decentralised perpetuals exchanges on Arbitrum were emptied: Ostium on 15 July, AFX Trade on 22 July. Together the attackers took roughly $42 million.

In both cases the entry point was not a smart contract but a private key held by people. That is where the industry's central marketing promise starts to crack. "Decentralised" has meant: nobody can take your money because nobody holds it. With many providers it actually means the deposit sits behind a bridge whose signing keys are kept on servers users know nothing about.

The two cases in detail

Ostium, 15 July

At the Arbitrum perp DEX Ostium, the private key of a price oracle was compromised. That allowed fake, future-dated price reports to be signed and fed through the protocol's own PriceUpKeep infrastructure. The attacker opened a position at a fabricated bitcoin price of $5,000 and closed it at the actual price of around $60,000. The difference came out of the liquidity providers' vault: $18 million to $23.75 million, depending on the assessment. Trading was suspended.

One detail from the bug bounty programme stands out: the exact component the attack ran through was explicitly excluded from it. Security researchers therefore had no incentive to look there. Security firm Halborn has reconstructed the attack step by step.

AFX Trade, 22 July

A week later it was AFX Trade, also on Arbitrum. The attacker gained control of the validator signing keys for the USDC custody bridge the protocol operates itself, through which cross-chain withdrawals are authorised. $24.15 million USDC left the platform. The funds were moved to Ethereum and swapped into roughly 12,467 ETH; the platform's total value locked was effectively empty afterwards.

AFX offered the attacker 30 percent of the sum as a so-called white hat bounty — about $7.2 million — in exchange for returning the rest. No return has been confirmed. Bridge operations were suspended, the infrastructure rebuilt and credentials rotated. On 3 August the project announced a goodwill plan for those affected. Our report on the incident: AFX Trade hack — Arbitrum perp DEX loses $24M as bridge keys are compromised.

The shared pattern

Both attacks follow the same logic. Trading itself runs on-chain, verifiable and without a custodian. At two points, though, the chain has to leave the blockchain:

  • At the price. A perpetual needs an external quote. Whoever holds the oracle key determines what the protocol treats as reality.
  • At the money. Deposits from other chains arrive over a bridge. Whoever holds its signing keys can withdraw.

Both are off-chain keys held by a small group. Neither the smart contract audit nor the decentralisation of the order book says anything about them. A perp DEX ends up as decentralised as its key management, and for many providers that is simply a company with servers.

For context: DeFi has already lost more than $840 million to hacks in 2026. The two July cases are not outliers in that series.

Perp DEXs compared: fees, liquidity, key architecture and incident history at a glancePerp DEXs compared: fees, liquidity, key architecture and incident history at a glance

The segment is shrinking anyway

PeriodMonthly volume across all perp DEXs
October 2025 (peak)$1.36 trillion
March 2026$699 billion
4 April 2026daily volume $8.4 billion, the first sub-$10 billion print since September 2025

That is a decline of more than 50 percent across five consecutive months, with no meaningful counter-move. The market has also reshuffled: Hyperliquid held around 71 percent of on-chain perp volume in May 2025 and now sits near a third. The reason is less migration than the division of a smaller overall market — Aster with incentive programmes, Lighter with a zero-fee model.

For users that means thinner order books, higher slippage and rising liquidation risk. There is also a side effect that is harder to see: providers under cost pressure economise, and security architecture is where economising stays unnoticed the longest.

Who is behind it?

A regulated exchange states in its imprint who is liable. A perp DEX, in case of doubt, offers a Discord handle. That is not an accusation but part of the design. It has a consequence that rarely features in the marketing: if the keys sit with people, then the question of who those people are is a security question.

Seven points can be clarified before your first deposit, and they say more than an audit certificate:

  1. Who holds the bridge keys? A single signer, a multisig or a distributed validator set? How many signatures does a withdrawal require, and who signs?
  2. Where does the price come from? A single oracle with one key is a single point of failure; several independent feeds with sanity checks are not.
  3. What is excluded from the bug bounty scope? Ostium showed that the exclusions are the most interesting passage of the programme.
  4. Is there an insurance fund, and is it visible on-chain? A commitment in a blog post is not a fund.
  5. Who is behind the project? Anonymous teams are not automatically dishonest, but they are not accountable either. That is worth knowing before depositing.
  6. How was communication handled in past incidents? Was there a technical post-mortem with a timeline, or only an announcement without figures?
  7. Where are users directed after an incident? If the same channels that promoted a platform then funnel users to one particular centralised exchange, that is an advertising relationship and belongs disclosed as one.

Our own position

Screenshots and claims about links between the AFX orbit and particular centralised exchanges are circulating in German-language groups. We could not verify that material independently and therefore name no names. A screenshot is not evidence, and a suspicion you cannot test does not belong in a headline. Anyone with material that holds up can contact our newsroom.

What we can say from our own experience: we also assess trading platforms by how they respond to editorial enquiries. With Phemex that experience has repeatedly been unsatisfactory, which is why the exchange appears in none of our recommendations. That is an assessment of our own dealings and not an allegation of misconduct towards users.

Prefer a counterparty you can reach? Every exchange with a MiCA licence in Europe, comparedPrefer a counterparty you can reach? Every exchange with a MiCA licence in Europe, compared

What to take away

The most uncomfortable conclusion of this summer is one the scene voices reluctantly: regulated, centralised exchanges have an argument again.

Not because they are technically superior, but because they offer something an anonymous perp DEX structurally cannot — an address you can serve papers to, a supervisor, a balance sheet, and somebody who is liable when keys go missing. Since the last MiCA transition period expired on 1 July 2026, it is also possible in Europe to look up who holds the relevant authorisation.

This is explicitly not an invitation to leave funds on an exchange permanently; "not your keys, not your coins" still holds. It is an invitation to price convenience honestly. At a regulated exchange you pay in fees and KYC. At an anonymous perp DEX you pay with the risk that a validator key changes hands on an ordinary Tuesday morning.

Three steps follow from that:

  1. Separate your holdings. Trading margin sits on the platform, nothing more. The rest belongs in your own custody. The AFX users who parked capital there have been waiting since 22 July for a goodwill plan. Which hardware wallet fits is covered in our hardware wallet comparison.
  2. Run the seven questions before your next deposit. It takes a few minutes. If you cannot answer them, you already have your answer. Providers side by side — fees, liquidity, key architecture, incident history — are in our perp DEX comparison.
  3. At least do the maths on the regulated route. If you do not need leverage, a regulated exchange costs a few basis points more and gives you a counterparty. In a market with halved volume, that is rarely the worse deal.

The question worth asking from here is less "is this decentralised?" than "who holds the keys, and what happens when that person has a bad day?". Decentralisation is not a property a logo promises but one that can be counted.

(As of 5 August 2026. This article is not investment advice and not a recommendation of any individual trading platform. Loss figures follow the analyses available at the time of publication and may change.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.

More from CryptoTicker